NtdsAudit is a credential-dumping tool used to extract domain user password hashes from Microsoft Active Directory data, specifically by operating on copies of the NTDS.dit database together with the SYSTEM registry hive. In the provided reporting, Chimera is explicitly documented using NtdsAudit via the command msadcs.exe "NTDS.dit" -s "SYSTEM" -p RecordedTV_pdmp.txt --users-csv RecordedTV_users.csv to dump password hashes of domain users. The same reporting states that Chimera gathered the SYSTEM registry and NTDS.dit files from target systems and used ntdsutil to copy the Active Directory database before using NtdsAudit. The tool is therefore associated with credential access against Windows domain controllers and Active Directory environments. High-confidence indicators from the content include the tool name NtdsAudit, execution via msadcs.exe, and the referenced output artifacts RecordedTV_pdmp.txt and RecordedTV_users.csv. The only threat actor directly associated with this tool in the provided content is Chimera.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Chimera specifically has used the NtdsAudit tool to dump the password hashes of domain users via msadcs.exe "NTDS.dit" -s "SYSTEM" -p RecordedTV_pdmp.txt --users-csv RecordedTV_users.csv
1 distinct technique documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tool used to extract/dump domain user password hashes from NTDS.dit (offline AD database analysis).
Utility used to extract and audit credentials from Active Directory database artifacts (e.g., NTDS.dit and SYSTEM hive), enabling domain credential compromise.
Tool used to extract/dump password hashes for domain users from Active Directory database artifacts (e.g., NTDS.dit and SYSTEM hive).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.