Suspicious access to Active Directory domain database

Detects suspicious access to the Active Directory domain database. Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information.

Back to all rules