NTDS.DIT Creation By Uncommon Process (11b1ed55-154d-4e82-8ad7-83739298f720)
Detects creation of a file named "ntds.dit" (Active Directory Database) by an uncommon process or a process located in a suspicious directory
Detects creation of a file named "ntds.dit" (Active Directory Database) by an uncommon process or a process located in a suspicious directory