Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
31 rules
Active Directory Database Dump via Ntdsutil IFM
This rule detects ntdsutil.exe creating an Install From Media snapshot to dump the ntds.dit Active Directory database, a domain credential theft step observed in the DeadRinger campaign against telcos. Extracting ntds.dit yields every domain account hash and is a high-impact credential access technique.
HuntRule TeamWindowsprocess_creationHigh00Premium2026-09-13Malicious NTDS.dit Extraction via Ntdsutil (via process_creation)
This rule detects ntdsutil creating an Install From Media snapshot of the Active Directory database, the domain credential theft step used in Rhysida ransomware intrusions. Dumping NTDS.dit exposes every domain hash and is a high-severity precursor to full domain compromise.
HuntRule TeamWindowsprocess_creationHigh10Premium2026-09-09Malicious NTDS Extraction via ntdsutil IFM (via process_creation)
This rule detects use of ntdsutil to create an Install From Media copy of the Active Directory database. Qilin ransomware operators ran ntdsutil with the ifm create full arguments to extract the NTDS database and registry hives for offline credential harvesting.
HuntRule TeamWindowsprocess_creationHigh40Premium2026-09-07Malicious NTDS Database Staging to Audit Directory (via file_event)
This rule detects creation of an ntds.dit Active Directory database copy under a C drive audit Active Directory path. During the Anubis ransomware intrusion the operators exfiltrated domain credentials by copying the NTDS database into an audit directory and archiving it, an activity that does not occur during normal operations.
HuntRule TeamWindowsfile_eventHigh50Premium2026-09-06Malicious NTDS Extraction via NetExec (via process_creation)
This rule detects the NetExec nxc binary invoking its NTDS module over SMB to extract the Active Directory database. This was used to steal domain credential hashes en masse before ransomware deployment. Bulk NTDS extraction provides every domain account hash and enables full domain takeover.
HuntRule TeamWindowsprocess_creationHigh133Premium2026-08-05Malicious Active Directory Database Dump via ntdsutil IFM (via process_creation)
This rule detects ntdsutil.exe invoked to create a full Install-From-Media snapshot of the Active Directory database, the credential-dumping step observed on domain controllers prior to NTDS.dit exfiltration. Adversaries leverage ntdsutil to extract every domain hash in one operation, making detection of the IFM and full snapshot subcommands critical for catching domain-wide credential theft.
HuntRule TeamWindowsprocess_creationHigh141Premium2026-08-03Malicious NTDS Extraction via Ntdsutil IFM Media Creation
This rule detects use of ntdsutil to create an install from media snapshot which extracts the Active Directory database and this technique was used during the NetSupport intrusion to steal the domain credential store and this matters because IFM creation dumps every domain hash in one operation and is almost never run by legitimate operators outside of controlled domain controller provisioning.
HuntRule TeamWindowsprocess_creationHigh392Premium2026-07-26Malicious NTDS.dit Extraction via ntdsutil IFM Snapshot (via process_creation)
This rule detects use of ntdsutil to create an install-from-media snapshot, the technique Storm-1175 uses to extract the NTDS.dit Active Directory database and steal domain credential hashes during Medusa ransomware operations. Adversaries dump NTDS.dit to obtain every domain account hash for offline cracking and mass lateral movement, so this command on a domain controller is a critical credential-access alert.
HuntRule TeamWindowsprocess_creationHigh111Premium2026-07-23Suspicious NTDS Database Access via Command Line (via process_creation)
This rule detects command lines referencing the ntds.dit Active Directory database, which was staged along with the SECURITY and SYSTEM registry hives for credential extraction in a ShadowPad intrusion. Access to ntds.dit outside of backup software is a strong credential theft indicator. Copying the directory database yields every domain account hash for offline cracking and forgery.
HuntRule TeamWindowsprocess_creationMedium102Premium2026-07-06Malicious NTDS.dit Copy for Domain Credential Theft (via file_event)
This rule detects an ntds.dit Active Directory database file being written to disk, the credential-theft step where Muddled Libra copies the domain database and SYSTEM hive from a mounted VMDK. Extracting ntds.dit yields every domain account hash for offline cracking and full domain compromise.
HuntRule TeamWindowsfile_eventHigh275Premium2026-07-04Suspicious NTDS Database Dump File Creation
This rule detects creation of files with an NTDS dump naming pattern which ransomware operators produce when extracting the Active Directory database for offline credential theft. Observed in NCC Group research into active ransomware families dumping NTDS content to text files. Capturing NTDS extraction artifacts helps detect domain-wide credential theft.
HuntRule TeamWindowsfile_eventMedium439Premium2026-06-24Malicious NTDS Credential Theft via Volume Shadow Copy via process_creation
This rule detects volume shadow copy creation with vssadmin or direct references to the ntds.dit Active Directory database used to steal domain credentials. Stately Taurus used vssadmin and NTDS.dit access on a compromised domain controller to harvest the credential store, a high-confidence sign of domain-wide credential access.
HuntRule TeamWindowsprocess_creationHigh251Premium2026-06-23Malicious NTDS Database Dump via NTDSUtil in BlackSuit Ransomware
This rule detects ntdsutil being used to create an installation from media (IFM) copy of the Active Directory database, a credential-access technique observed in BlackSuit ransomware intrusions. Dumping NTDS.dit gives operators every domain hash for offline cracking and full domain compromise, making this a critical detection.
HuntRule TeamWindowsprocess_creationHigh403Premium2026-06-19Suspicious NTDS Database Extraction from System Volume
This rule detects command-line references to the NTDS.dit Active Directory database being copied or dumped, a credential-theft step seen in CitrixBleed post-exploitation. Attackers extract NTDS.dit to harvest domain credential hashes for offline cracking and further compromise. Because access to this file outside of backup or DC maintenance is rare, it is a strong indicator of domain credential theft.
HuntRule TeamWindowsprocess_creationMedium143Premium2026-06-08Malicious NTDS Database Extraction via Ntdsutil (via process_creation)
This rule detects ntdsutil creating a full copy of the Active Directory database, the credential theft step Volt Typhoon performs to obtain the domain NTDS.dit file and all account hashes. Dumping the directory database enables offline cracking and domain wide impersonation, so this operation on a domain controller is a high confidence indicator of hands on keyboard credential access.
HuntRule TeamWindowsprocess_creationHigh239Premium2026-05-25