Sagan medium stable other

[EXTRAHOP] AD Credential Theft with ntdsutil

[EXTRAHOP] AD Credential Theft with ntdsutil

View Source

Detection Logic

pass any $HOME_NET any -> $HOME_NET any (msg:"[EXTRAHOP] AD Credential Theft with ntdsutil"; program:exabeam-api_data; json_content:".alert_name","AD Credential Theft with ntdsutil"; json_contains; parse_src_ip:1; normalize; reference:url,https://docs.extrahop.com/25.2/detections-overview/; classtype:suspicious-activity; sid:5016272; rev:1; metadata:deployment Endpoint,affected_product NONE,affected_version NONE,mitigation NONE,deprecation_reason NONE,tag NONE, created_at 2025_06_18, updated_at 2025_06_18, mitre_tactic_id T1003;)

Field Validations

Loading…

Comments (0)

Loading comments...