Hide Navigation Hide TOC Suspicious Process Patterns NTDS.DIT Exfil (8bc64091-6875-4881-aaf9-7bd25b5dda08) Detects suspicious process patterns used in NTDS.DIT exfiltration Cluster A Galaxy A Cluster B Galaxy B Level Suspicious Process Patterns NTDS.DIT Exfil (8bc64091-6875-4881-aaf9-7bd25b5dda08) Sigma-Rules NTDS - T1003.003 (edf91964-b26e-4b4a-9600-ccacd7d7df24) Attack Pattern 1 NTDS - T1003.003 (edf91964-b26e-4b4a-9600-ccacd7d7df24) Attack Pattern OS Credential Dumping - T1003 (0a3ead4e-6d47-4ccb-854c-a6a4f9d96b22) Attack Pattern 2