ntdsutil IFM full create staging NTDS.dit under C:\Windows\Temp
Detects the use of ntdsutil.exe to create an Install From Media (IFM) set, which copies the NTDS.dit file and registry hives to a specified folder. Adversaries often use this technique to stage Active Directory credentials for exfiltration, frequently using the C:\Windows\Temp directory as a staging area. The rule includes exclusions for common legitimate system management and backup agents.
Microsoft Sentinel (KQL)

