Skip to content

Instantly share code, notes, and snippets.

@besimorhino
besimorhino / include_ntdsutil.xml
Created August 11, 2022 18:38
sysmon xml filter to monitor use of ntdsutil.exe
<Sysmon schemaversion="4.30">
<EventFiltering>
<RuleGroup name="" groupRelation="or">
<ProcessCreate onmatch="include">
<OriginalFileName name="technique_id=T1003.003,technique_name=OS Credential Dumping: NTDS" condition="is">ntdsutil.exe</OriginalFileName>
</ProcessCreate>
</RuleGroup>
</EventFiltering>
</Sysmon>