Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
3 rules
Suspicious ntdsutil.exe Use for AD Snapshot Mount or Activation (Windows Process Creation)
Alerts on ntdsutil.exe command lines that include snapshot mount and activation/instance fragments, indicating potential AD snapshot manipulation.
sigmaWindowsmedium2022-09-14Windows ntdsutil Abuse Indicators via ESENT Events Containing ntds.dit
Flags ESENT application events mentioning ntds.dit that may indicate ntdsutil attempts to access the AD database.
sigmaWindowsmedium2022-08-14Windows: Execution of ntdsutil.exe for NTDS database operations
Flags execution of ntdsutil.exe, a utility that can be used to manipulate the NTDS database (NTDS.DIT).
sigmaWindowsmedium2019-01-16