Windows: Detect ESENT New Database Created with ntds.dit Written to Suspicious Path

Identifies ESENT EventID 325 where a new database containing ntds.dit is created in suspicious locations.

FreeReviewedSigma · Medium · v2
Product
windows
Service
application
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-08-14
Updated
2026-07-31

What it detects

This rule flags Windows application events where ESENT reports a new database being created and the event data contains "ntds.dit", indicating a potential ntdsutil-based dump of the Active Directory database to an unusual location. Such activity is important because exporting ntds.dit can enable credential and directory data theft. It relies on Windows application telemetry from ESENT, specifically events with EventID 325 and event data containing "ntds.dit" and a suspicious destination-like path segment.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.