NTDS Exfiltration Filename Patterns

 Original Source: [Sigma source]
Title: NTDS Exfiltration Filename Patterns
Status: test
Description:Detects creation of files with specific name patterns seen used in various tools that export the NTDS.DIT for exfiltration.
References:
  -https://github.com/rapid7/metasploit-framework/blob/eb6535009f5fdafa954525687f09294918b5398d/modules/post/windows/gather/ntds_grabber.rb
  -https://github.com/rapid7/metasploit-framework/blob/eb6535009f5fdafa954525687f09294918b5398d/data/post/powershell/NTDSgrab.ps1
  -https://github.com/SecureAuthCorp/impacket/blob/7d2991d78836b376452ca58b3d14daa61b67cb40/impacket/examples/secretsdump.py#L2405
Author: Florian Roth (Nextron Systems)
Date: 2022-03-11
modified:2023-05-05
Tags:
  • -'attack.credential-access'
  • -'attack.t1003.003'
Logsource:
  • product: windows
  • category: file_event
Detection:
  selection:
    TargetFilename|endswith:
      -'\All.cab'
      -'.ntds.cleartext'

  condition:selection
Falsepositives:
  -Unknown
Level: high