Demo Overview: Managed Mobile Productivity - Microsoft

The ACSC identified the actor utilising the native Windows tool Ntdsutil to create a copy of the Active Directory database. While this database could be used as part of a number of tactics and techniques, especially the Discovery tactic, a key use is to access credentials for Windows Domain accounts stored within the database. ................
................