NTDSDump is a credential-dumping tool used to extract account credential material from Microsoft Active Directory environments, particularly from domain controllers. It is associated with theft of password hashes and related directory data from the NTDS database, enabling follow-on activities such as privilege escalation, persistence, lateral movement, and broader domain compromise. The tool has been observed in intrusion activity attributed to China-linked threat actors including Ke3chang, and has also been referenced alongside other credential-access utilities such as Mimikatz and WDigest in operations involving Kerberos abuse and domain-wide credential theft. NTDSDump targets Windows enterprise environments and is used during post-compromise operations to gather credentials from Active Directory rather than as an initial access mechanism.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Indicators of Compromise SHA-1 Malware Family 2367326f995cb911c72baadc33a3155f8f674600 NTDSDump
MSTIC found that the same threat actor used malicious tools such as Mimikatz, WDigest, NTDSDump, and other password-dumping tools to gather credentials on a targeted system.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
After the loader and payload pairs were successfully installed, the attacker started poking around the environments with tools like password dumpers...
"APT28 has used the ntdsutil.exe utility to export the Active Directory database for credential access"; "Chimera ... gathered the SYSTEM registry and ntds.dit files"; "Impacket SecretsDump and Mimikatz modules ... obtain account and password information from NTDS.dit"; "Wizard Spider ... gained access to credentials via exported copies of the ntds.dit Active Directory database"
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A password-dumping tool mentioned as part of credential theft activity supporting forged-ticket attacks.
Credential-dumping tool listed in the indicators of compromise and consistent with the attackers obtaining account usernames and passwords from the victim environment.
Credential dumping tool used to extract credentials/hashes from Active Directory (NTDS-related sources).
Password/credential dumping tool used to extract credentials from Active Directory-related sources (e.g., NTDS).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.