FORENSIA

ATT&CK · T1003.003 · sub-technique

NTDS

Tactics: credential-access

About

Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as devices, users, and access rights. By default, the NTDS file (NTDS.dit) is located in <code>%SystemRoot%\NTDS\Ntds.dit</code> of a domain controller. In addition to looking for NTDS files on active Domain Controllers, adversaries may search for backups that contain the same or similar information. The following tools and techniques can be used to enumerate the NTDS file and the contents of the entire Active Directory hashes. * Volume Shadow Copy * secretsdump.py * Using the in-built Windows tool, ntdsutil.exe * Invoke-NinjaCopy

Corpus indicators tagged with this technique

37 indicators in the corpus carry T1003.003.

IndicatorTypeFamilySevSrc
cve-2021-27076cve851
a6df0b49a5ef9ffd6513bfe061fb60f6d2941a440038e2de8a7aeb1914945331sha256ransomware801
6ba5d96e52734cbb9246bcc3decf127f780d48fa11587a1a44880c1f04404d23sha256ransomware801
18b8e6762afd29a09becae283083c74a19fc09db1f2c3412c42f1b0178bc122asha256ransomware801
a14506c6fb92a5af88a6a44d273edafe10d69ee3d85c8b2a7ac458a22edf68d2sha256ransomware801
6a5f9bd0e4a0c385b98cc7b528be53a95ff9c4ccffa8c1f65448ab792a46186csha256801
186b26df63df3b7334043b47659cba4185c948629d857d47452cc1936f0aa5dasha256ransomware801
23fd50b3bcc06f5adcbd0122c32260786ec3b98asha1781
1b9aa401457d29405c0bcf19cbf19a7028a0d214sha1ransomware781
f352cec89a56e23dae20cdd62df4d40bc7f22b5esha1ransomware781
febbaf5f08a8e0782ffcce8beef1f2b4e249a52bsha1ransomware781
bcee0ab10b23f5999bcdb56c0b4a631amd5ransomware761
24fcebdeecba65004fdb0923763d74fdmd5761
9c872a0d5d5a38950e8b9ac9b488be3fmd5761
9cbd560f820c95d7c38342cd558cb5c6md5761
a514d1bb62d7916475946fe7c07ac0aamd5761
aa3086be652c8b20b0b29b2730d57119md5761
b3352b42432dedc4a519f011dc8b5d5amd5761
c559cc68986933200fd5d9e4388e2f58md5761
d98f568496512e4f98670c61c97cb07amd5761
1f65544978b8ea0e745e573b8ee9684bmd5769
a746da514c90f26a187a294fda7edc1bmd5ransomware761
ca8646dfc88423bb9fffda811160cebemd5ransomware761
193.242.184.150ipransomware701
109.205.195.211ipransomware701
172.96.137.160ipransomware701
ms-record.comdomain651
opmanager.prodomainransomware651
2rxyt9urhq0bgj.orgdomainransomware651
axiscamerastation.orgdomainransomware651

Showing the top 30 by severity of 37.