Skip to content

Hide Navigation Hide TOC

PUA - DIT Snapshot Viewer (d3b70aad-097e-409c-9df2-450f80dc476b)

Detects the use of Ditsnap tool, an inspection tool for Active Directory database, ntds.dit.

Cluster A Galaxy A Cluster B Galaxy B Level
NTDS - T1003.003 (edf91964-b26e-4b4a-9600-ccacd7d7df24) Attack Pattern PUA - DIT Snapshot Viewer (d3b70aad-097e-409c-9df2-450f80dc476b) Sigma-Rules 1
NTDS - T1003.003 (edf91964-b26e-4b4a-9600-ccacd7d7df24) Attack Pattern OS Credential Dumping - T1003 (0a3ead4e-6d47-4ccb-854c-a6a4f9d96b22) Attack Pattern 2