Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
31 rules
Malicious VOLTZITE NTDS.dit Credential Staging in Temp Directory (via process_creation)
This rule detects command lines that reference the Active Directory database file ntds.dit together with copy or staging operations into temporary and world-writable directories. VOLTZITE stages ntds.dit in local and temp folders to extract domain credentials from compromised infrastructure. Access to the domain database enables offline password hash extraction and broad lateral movement.
HuntRule TeamWindowsprocess_creationHigh507Premium2026-05-24Malicious NTDS.dit Access via esentutl Database Copy (via process_creation)
This rule detects esentutl.exe operating on the ntds.dit Active Directory database file, an operation used during this intrusion to copy or process the domain credential store extracted from a volume shadow copy. Adversaries leverage the esentutl LOLBin to handle the locked database and recover hashes, making detection of ntds.dit in its command line a strong credential-access signal.
HuntRule TeamWindowsprocess_creationHigh162Premium2026-05-08Malicious Active Directory Database (NTDS.dit) Extraction (via process_creation)
This rule detects extraction of the Active Directory database via ntdsutil Install-From-Media snapshots or shadow-copy access to ntds.dit, which yields every domain credential hash for offline cracking and forging. NTDS credential access is a high-impact technique in the Red Canary Threat Detection Report and a common precursor to domain-wide compromise. Detecting these extraction commands surfaces a domain-controller-level credential theft.
HuntRule TeamWindowsprocess_creationCritical246Premium2026-05-06Windows Print.EXE Sensitive File Dump for Credential Access
Alerts when Print.EXE is executed with arguments targeting ntds.dit, SAM, SECURITY, and SYSTEM files for credential access.
Ayush Anand (Securityinbits), Huntrule TeamWindowsprocess_creationHigh111Free2026-04-28Windows: wbadmin.exe Used to Recover/Dump Sensitive Registry Hives and NTDS.dit
Alert on wbadmin.exe recovery commands targeting SAM/SECURITY/SYSTEM hives and NTDS.dit.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationHigh100Free2024-05-10Windows Process Creation: wbadmin.exe Triggered for Backup of Sensitive Registry and NTDS Files
Alerts on wbadmin.exe backup commands that reference SAM/SECURITY/SYSTEM hives or NTDS.DIT.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationHigh288Free2024-05-10Windows: File Creation of NTDS.DIT (Active Directory Database)
Flags creation of an ntds.dit file on Windows, an Active Directory database artifact often associated with credential access.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventLow172Free2023-05-05Suspicious ntdsutil.exe Use for AD Snapshot Mount or Activation (Windows Process Creation)
Alerts on ntdsutil.exe command lines that include snapshot mount and activation/instance fragments, indicating potential AD snapshot manipulation.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium183Free2022-09-14Windows: Detect ESENT New Database Created with ntds.dit Written to Suspicious Path
Identifies ESENT EventID 325 where a new database containing ntds.dit is created in suspicious locations.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsapplicationMedium90Free2022-08-14Windows ntdsutil Abuse Indicators via ESENT Events Containing ntds.dit
Flags ESENT application events mentioning ntds.dit that may indicate ntdsutil attempts to access the AD database.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsapplicationMedium100Free2022-08-14Windows PowerShell: Suspicious Get-ADDBAccount access to ntds.dit via BootKey and DatabasePath
Alerts on PowerShell invocations of Get-ADDBAccount that reference BootKey and DatabasePath for ntds.dit credential access.
Florian Roth (Nextron Systems), Huntrule TeamWindowsps_moduleHigh133Free2022-03-16Windows Process Creation: Detect NTDS.DIT and Registry Hive Exfiltration Tooling
Detects suspicious Windows processes that reference NTDS.DIT/SYSTEM hive dumping or staging via common NTDS tooling and scripts.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh173Free2022-03-11Windows NTDS Exfiltration File Creation by NTDS Export Filename Patterns
Alerts on Windows file creates using common NTDS-DIT dump/exfiltration filename suffixes like \All.cab and .ntds.cleartext.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh327Free2022-03-11Windows File Events: NTDS.DIT Created by Suspicious or Rare Process
Alerts on creation of ntds.dit on Windows when the creator process image/path is uncommon or located in suspicious directories.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh131Free2022-01-11Windows: Detect esentutl.exe Copying Sensitive Credential Files via VSS
Alerts on esentutl.exe VSS usage and command lines referencing SAM/SECURITY/SYSTEM or ntds.dit copy targets.
Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowsprocess_creationHigh122Free2019-10-22