Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
11 rules
Active Directory Database Dump via Ntdsutil IFM
This rule detects ntdsutil.exe creating an Install From Media snapshot to dump the ntds.dit Active Directory database, a domain credential theft step observed in the DeadRinger campaign against telcos. Extracting ntds.dit yields every domain account hash and is a high-impact credential access technique.
HuntRule TeamWindowsprocess_creationHigh00Premium2026-09-13Malicious NTDS.dit Extraction via Ntdsutil (via process_creation)
This rule detects ntdsutil creating an Install From Media snapshot of the Active Directory database, the domain credential theft step used in Rhysida ransomware intrusions. Dumping NTDS.dit exposes every domain hash and is a high-severity precursor to full domain compromise.
HuntRule TeamWindowsprocess_creationHigh10Premium2026-09-09Malicious NTDS Extraction via ntdsutil IFM (via process_creation)
This rule detects use of ntdsutil to create an Install From Media copy of the Active Directory database. Qilin ransomware operators ran ntdsutil with the ifm create full arguments to extract the NTDS database and registry hives for offline credential harvesting.
HuntRule TeamWindowsprocess_creationHigh40Premium2026-09-07Malicious Active Directory Database Dump via ntdsutil IFM (via process_creation)
This rule detects ntdsutil.exe invoked to create a full Install-From-Media snapshot of the Active Directory database, the credential-dumping step observed on domain controllers prior to NTDS.dit exfiltration. Adversaries leverage ntdsutil to extract every domain hash in one operation, making detection of the IFM and full snapshot subcommands critical for catching domain-wide credential theft.
HuntRule TeamWindowsprocess_creationHigh141Premium2026-08-03Malicious NTDS Extraction via Ntdsutil IFM Media Creation
This rule detects use of ntdsutil to create an install from media snapshot which extracts the Active Directory database and this technique was used during the NetSupport intrusion to steal the domain credential store and this matters because IFM creation dumps every domain hash in one operation and is almost never run by legitimate operators outside of controlled domain controller provisioning.
HuntRule TeamWindowsprocess_creationHigh392Premium2026-07-26Malicious NTDS.dit Extraction via ntdsutil IFM Snapshot (via process_creation)
This rule detects use of ntdsutil to create an install-from-media snapshot, the technique Storm-1175 uses to extract the NTDS.dit Active Directory database and steal domain credential hashes during Medusa ransomware operations. Adversaries dump NTDS.dit to obtain every domain account hash for offline cracking and mass lateral movement, so this command on a domain controller is a critical credential-access alert.
HuntRule TeamWindowsprocess_creationHigh111Premium2026-07-23Malicious NTDS Database Dump via NTDSUtil in BlackSuit Ransomware
This rule detects ntdsutil being used to create an installation from media (IFM) copy of the Active Directory database, a credential-access technique observed in BlackSuit ransomware intrusions. Dumping NTDS.dit gives operators every domain hash for offline cracking and full domain compromise, making this a critical detection.
HuntRule TeamWindowsprocess_creationHigh393Premium2026-06-19Malicious NTDS Database Extraction via Ntdsutil (via process_creation)
This rule detects ntdsutil creating a full copy of the Active Directory database, the credential theft step Volt Typhoon performs to obtain the domain NTDS.dit file and all account hashes. Dumping the directory database enables offline cracking and domain wide impersonation, so this operation on a domain controller is a high confidence indicator of hands on keyboard credential access.
HuntRule TeamWindowsprocess_creationHigh239Premium2026-05-25Suspicious ntdsutil.exe Use for AD Snapshot Mount or Activation (Windows Process Creation)
Alerts on ntdsutil.exe command lines that include snapshot mount and activation/instance fragments, indicating potential AD snapshot manipulation.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium183Free2022-09-14Windows ntdsutil Abuse Indicators via ESENT Events Containing ntds.dit
Flags ESENT application events mentioning ntds.dit that may indicate ntdsutil attempts to access the AD database.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsapplicationMedium100Free2022-08-14Windows: Execution of ntdsutil.exe for NTDS database operations
Flags execution of ntdsutil.exe, a utility that can be used to manipulate the NTDS database (NTDS.DIT).
Thomas Patzke, Huntrule TeamWindowsprocess_creationMedium185Free2019-01-16