Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
13 rules
Windows Print.EXE Sensitive File Dump for Credential Access
Alerts when Print.EXE is executed with arguments targeting ntds.dit, SAM, SECURITY, and SYSTEM files for credential access.
sigmaWindowshigh2026-04-28Windows: wbadmin.exe Used to Recover/Dump Sensitive Registry Hives and NTDS.dit
Alert on wbadmin.exe recovery commands targeting SAM/SECURITY/SYSTEM hives and NTDS.dit.
sigmaWindowshigh2024-05-10Windows Process Creation: wbadmin.exe Triggered for Backup of Sensitive Registry and NTDS Files
Alerts on wbadmin.exe backup commands that reference SAM/SECURITY/SYSTEM hives or NTDS.DIT.
sigmaWindowshigh2024-05-10Windows: File Creation of NTDS.DIT (Active Directory Database)
Flags creation of an ntds.dit file on Windows, an Active Directory database artifact often associated with credential access.
sigmaWindowslow2023-05-05Suspicious ntdsutil.exe Use for AD Snapshot Mount or Activation (Windows Process Creation)
Alerts on ntdsutil.exe command lines that include snapshot mount and activation/instance fragments, indicating potential AD snapshot manipulation.
sigmaWindowsmedium2022-09-14Windows: Detect ESENT New Database Created with ntds.dit Written to Suspicious Path
Identifies ESENT EventID 325 where a new database containing ntds.dit is created in suspicious locations.
sigmaWindowsmedium2022-08-14Windows ntdsutil Abuse Indicators via ESENT Events Containing ntds.dit
Flags ESENT application events mentioning ntds.dit that may indicate ntdsutil attempts to access the AD database.
sigmaWindowsmedium2022-08-14Windows PowerShell: Suspicious Get-ADDBAccount access to ntds.dit via BootKey and DatabasePath
Alerts on PowerShell invocations of Get-ADDBAccount that reference BootKey and DatabasePath for ntds.dit credential access.
sigmaWindowshigh2022-03-16Windows Process Creation: Detect NTDS.DIT and Registry Hive Exfiltration Tooling
Detects suspicious Windows processes that reference NTDS.DIT/SYSTEM hive dumping or staging via common NTDS tooling and scripts.
sigmaWindowshigh2022-03-11Windows NTDS Exfiltration File Creation by NTDS Export Filename Patterns
Alerts on Windows file creates using common NTDS-DIT dump/exfiltration filename suffixes like \All.cab and .ntds.cleartext.
sigmaWindowshigh2022-03-11Windows File Events: NTDS.DIT Created by Suspicious or Rare Process
Alerts on creation of ntds.dit on Windows when the creator process image/path is uncommon or located in suspicious directories.
sigmaWindowshigh2022-01-11Windows: Detect esentutl.exe Copying Sensitive Credential Files via VSS
Alerts on esentutl.exe VSS usage and command lines referencing SAM/SECURITY/SYSTEM or ntds.dit copy targets.
sigmaWindowshigh2019-10-22Windows: Execution of ntdsutil.exe for NTDS database operations
Flags execution of ntdsutil.exe, a utility that can be used to manipulate the NTDS database (NTDS.DIT).
sigmaWindowsmedium2019-01-16