Skip to content

Siemphony is in beta and still being built. How a rule earns its badge.

Siemphony’s repertoire

Active Directory database file copied, exported or dumped

Matches a command line that names the Active Directory database or a tool that extracts it — ntds.dit itself, the NTDS directory on a domain controller, ntdsutil, whose install-from-media mode writes a full copy of the database, Invoke-NinjaCopy, which the technique names, and NTDSDumpEx, a closely related dumping utility added here. This is the only rule in the corpus keyed on the directory database: the neighbouring credential-dumping rules match handles opened against lsass.exe (T1003, T1003.001) or copies of the local SAM, SYSTEM and SECURITY hives (T1003.002, T1003.004), none of which touch a domain controller's NTDS. Shadow copy creation, which AN1611 also names, is deliberately not matched, because backup and imaging software creates shadow copies continuously and those hits would bury everything else. secretsdump.py, the other tool the technique names, has no selector either: its default DRSUAPI replication mode runs from a remote host against the domain controller's directory service and creates no process on the controller for this logsource to observe, so it is structurally out of scope here and only its local-file mode would match incidentally, through the ntds.dit term. The analytic's process source is Security EventID 4688, so Audit Process Creation must be enabled and, because every term here sits on the arguments, the separate Include command line in process creation events policy as well — with either one off this rule matches nothing while looking healthy. UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0586, not hand-written and not tested by its author. Any lab result is on this rule's own page.Full description

The detection

The 4 SIEM queries below are previews produced by Siemphony’s own translator, not pySigma, and none has been executed against a real backend — review before you deploy.

detection.yml

title: Active Directory database file copied, exported or dumpedid: 44618d2d-4365-4e90-a089-50cd102e9906status: experimentaldescription: |  Matches a command line that names the Active Directory database or a tool that  extracts it — ntds.dit itself, the NTDS directory on a domain controller,  ntdsutil, whose install-from-media mode writes a full copy of the database,  Invoke-NinjaCopy, which the technique names, and NTDSDumpEx, a closely related  dumping utility added here. This is the only rule in the corpus  keyed on the directory database: the neighbouring credential-dumping rules match  handles opened against lsass.exe (T1003, T1003.001) or copies of the local SAM,  SYSTEM and SECURITY hives (T1003.002, T1003.004), none of which touch a domain  controller's NTDS. Shadow copy creation, which AN1611 also names, is deliberately  not matched, because backup and imaging software creates shadow copies  continuously and those hits would bury everything else. secretsdump.py, the  other tool the technique names, has no selector either: its default DRSUAPI  replication mode runs from a remote host against the domain controller's  directory service and creates no process on the controller for this logsource to  observe, so it is structurally out of scope here and only its local-file mode  would match incidentally, through the ntds.dit term. The analytic's process  source is Security EventID 4688, so Audit Process Creation must be enabled and,  because every term here sits on the arguments, the separate Include command line  in process creation events policy as well — with either one off this rule matches  nothing while looking healthy.  UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0586, not hand-written and not tested by its author. Any lab result is on this rule's own page.references:  - https://attack.mitre.org/techniques/T1003/003  - https://attack.mitre.org/detectionstrategies/DET0586author: Siemphony pipeline (machine-derived from MITRE ATT&CK v19.2)date: 2026-08-16tags:  - attack.credential-access  - attack.t1003.003logsource:  category: process_creation  product: windowsdetection:  selection:    CommandLine|contains:      - 'ntds.dit'      - 'ntdsutil'      - 'Windows\NTDS'      - 'Invoke-NinjaCopy'      - 'NTDSDumpEx'  condition: selectionfalsepositives:  - "Domain controller promotion and demotion. The AD DS installation role writes and references the NTDS directory by path, and administrators build install-from-media sets with ntdsutil for a new or read-only controller, which is the same command an adversary uses to dump the database."  - "Scheduled offline maintenance of the directory database — compaction, integrity checks and semantic analysis are all run through ntdsutil and are routine domain controller housekeeping."  - "Backup, replication and disaster-recovery agents whose command lines name the NTDS path when they capture or restore system state on a domain controller. These recur on a fixed schedule under a service account, which is what MITRE's ParentProcessName knob is there to suppress."  - "Authorised red-team engagements and detection-validation suites, which run ntdsutil install-from-media and Invoke-NinjaCopy verbatim as part of a credential-access test."level: high

Sentinel · KQL

Run this as a search.

DeviceProcessEvents| where (ProcessCommandLine contains "ntds.dit" or ProcessCommandLine contains "ntdsutil" or ProcessCommandLine contains "Windows\\NTDS" or ProcessCommandLine contains "Invoke-NinjaCopy" or ProcessCommandLine contains "NTDSDumpEx")

Splunk · SPL

Run this as a search.

index=* (CommandLine="*ntds.dit*" OR CommandLine="*ntdsutil*" OR CommandLine="*Windows\\NTDS*" OR CommandLine="*Invoke-NinjaCopy*" OR CommandLine="*NTDSDumpEx*")

Elastic · ES|QL

Run this as a search.

FROM logs-*| WHERE (TO_LOWER(process.command_line) LIKE "*ntds.dit*" OR TO_LOWER(process.command_line) LIKE "*ntdsutil*" OR TO_LOWER(process.command_line) LIKE "*windows\\\\ntds*" OR TO_LOWER(process.command_line) LIKE "*invoke-ninjacopy*" OR TO_LOWER(process.command_line) LIKE "*ntdsdumpex*")

Wazuh · XML rule

Deploy to your manager — this is a rule, not a search.

<group name="sigma,windows,process_creation,">  <!-- Rule ids must be unique on your manager; 100000+ is the user range. -->  <rule id="100000" level="12">    <!-- Set <if_sid> to the decoder/base rule for windows so this only evaluates relevant events. -->    <field name="CommandLine" type="pcre2">(?i)(ntds\.dit|ntdsutil|Windows\\NTDS|Invoke-NinjaCopy|NTDSDumpEx)</field>    <description>Active Directory database file copied, exported or dumped</description>    <mitre>      <id>T1003.003</id>    </mitre>  </rule></group>

Verdicts · reactions · comments

Community

Verdicts from engineers who actually deployed it, and the conversation around it.

Log in to react
Not yet reported on

Nobody has run this in a real environment and said what happened.

Verdicts from engineers who deployed it

0 cast

No verdicts reported yet. The first one is worth more than the tenth — say what you ran it against.

Log in to report a verdict.

Log in to join the discussion.

No comments yet. Someone who deploys this will have something to say about it.