title: Invocation of Active Directory Diagnostic Tool (ntdsutil.exe) id: 2afafd61-6aae-4df4-baed-139fa1f4c345 description: Detects execution of ntdsutil.exe, which can be used for various attacks against the NTDS database (NTDS.DIT) status: experimental references: - https://jpcertcc.github.io/ToolAnalysisResultSheet/details/ntdsutil.htm author: Thomas Patzke date: 2019/01/16 tags: - attack.credential_access - attack.t1003 logsource: category: process_creation product: windows detection: selection: CommandLine: '*\ntdsutil*' condition: selection falsepositives: - NTDS maintenance level: high