esentutl is a legitimate Windows utility that can be abused as a dual-use collection and credential-access tool. The provided content states that it can be used to collect data from local file systems and can copy the Active Directory NTDS.dit database using the Volume Shadow Copy service. This behavior makes it relevant to collection of local data as well as theft of Active Directory credential material from domain controllers. The content does not attribute esentutl to a specific threat actor directly, but places it alongside broader tradecraft used to obtain NTDS.dit for credential dumping.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
"APT28 has used the ntdsutil.exe utility to export the Active Directory database for credential access"; "Chimera ... gathered the SYSTEM registry and ntds.dit files"; "Impacket SecretsDump and Mimikatz modules ... obtain account and password information from NTDS.dit"; "Wizard Spider ... gained access to credentials via exported copies of the ntds.dit Active Directory database" | "CrackMapExec can dump hashed passwords ... using ... Volume Shadow Copy"; "esentutl can copy ntds.dit using the Volume Shadow Copy service"; "Fox Kitten has used Volume Shadow Copy to access credential information from NTDS"; "Mustang Panda has used vssadmin to create a volume shadow copy and retrieve the NTDS.dit file"; "Wizard Spider ... created a volume shadow copy ... to collect NTDS.dit"
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Legitimate Windows database utility abused to copy the Active Directory database (NTDS.dit), often via Volume Shadow Copy, to facilitate offline credential extraction.
Legitimate Windows utility abused to collect data from local file systems.
Windows utility that can be abused to copy ESE database files (including NTDS.dit) often as part of credential access workflows.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.