Suspicious access to Active Directory domain database
Detects suspicious access to the Active Directory domain database. Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information.
- Platform: Windows
- Severity: High
- MITRE Tactic: Credential Access
- MITRE Techniques: T1003, T1003.003