Elastic Defend high stable eql

Suspicious Access to Active Directory Database File

Identifies access to the Active Directory Domain Database file (ntds.dit). This file contains sensitive information including hashed domain credentials.

View Source

Detection Logic

file where event.action == "open" and process.pid != 4 and 
 file.path : "*\\Windows\\NTDS\\ntds.dit" and process.executable : "?:\\*" and
 /* covered by RuleId 3c44fc50-2672-48b3-af77-ff43b895ac70 */
 not process.executable :
             ("?:\\Windows\\System32\\ntdsutil.exe",
              "?:\\Windows\\System32\\esentutl.exe",
              "?:\\Windows\\system32\\lsass.exe",
              "?:\\Windows\\System32\\wbengine.exe",
              "?:\\Program Files\\*.exe",
              "?:\\Program Files (x86)\\*.exe",
              "C:\\PCBP\\WBPS.exe",
              "?:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\*.exe", 
              "?:\\ProgramData\\Microsoft\\Windows Defender Advanced Threat Protection\\Platform\\*.exe",
              "?:\\Windows\\explorer.exe") and
 not (process.code_signature.subject_name in ("EFOLDER, INC.", "Avira Operations GmbH") and process.code_signature.trusted == true)

Field Validations

Loading…

Comments (0)

Loading comments...