Suspicious access to Active Directory domain database
Detects suspicious access to the Active Directory domain database. Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information.
- Plataforma: Windows
- Severidad: High
- Táctica MITRE: Acceso a credenciales
- Técnicas MITRE: T1003, T1003.003