NTDS.DIT Creation By Uncommon Process

 Original Source: [Sigma source]
Title: NTDS.DIT Creation By Uncommon Process
Status: test
Description:Detects creation of a file named "ntds.dit" (Active Directory Database) by an uncommon process or a process located in a suspicious directory
References:
  -https://stealthbits.com/blog/extracting-password-hashes-from-the-ntds-dit-file/
  -https://adsecurity.org/?p=2398
Author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Date: 2022-01-11
modified:2022-07-14
Tags:
  • -'attack.credential-access'
  • -'attack.t1003.002'
  • -'attack.t1003.003'
Logsource:
  • product: windows
  • category: file_event
Detection:
  selection_ntds:
    TargetFilename|endswith: '\ntds.dit'
  selection_process_img:
    Image|endswith:
      -'\cmd.exe'
      -'\cscript.exe'
      -'\mshta.exe'
      -'\powershell.exe'
      -'\pwsh.exe'
      -'\regsvr32.exe'
      -'\rundll32.exe'
      -'\wscript.exe'
      -'\wsl.exe'
      -'\wt.exe'

  selection_process_paths:
    Image|contains:
      -'\AppData\'
      -'\Temp\'
      -'\Public\'
      -'\PerfLogs\'

  condition:selection_ntds and 1 of selection_process_*
Falsepositives:
  -Unknown
Level: high