NtdsAudit is an Active Directory auditing and credential-extraction tool capable of dumping domain-user password hashes and exporting user information in CSV format. It processes an Active Directory database together with associated system registry data, targeting credential material from Windows domain controllers. Its credential-dumping behavior maps to MITRE ATT&CK sub-technique T1003.003, OS Credential Dumping: NTDS.
Chimera has used NtdsAudit during enterprise intrusions after collecting Active Directory database and system registry data. The actor has separately used the Windows ntdsutil utility to copy the database before credential extraction. NtdsAudit is a tool used in these operations, rather than a malware family with independently established delivery or persistence mechanisms.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Chimera specifically has used the NtdsAudit tool to dump the password hashes of domain users via cmsadcs.exe "NTDS.dit" -s "SYSTEM" -p RecordedTV_pdmp.txt --users-csv RecordedTV_users.csv.
1 distinct technique documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An auditing tool explicitly used by Chimera to extract domain-user password hashes from NTDS.dit using the SYSTEM registry hive.
Tool used to extract/dump domain user password hashes from NTDS.dit (offline AD database analysis).
Utility used to extract and audit credentials from Active Directory database artifacts (e.g., NTDS.dit and SYSTEM hive), enabling domain credential compromise.
Tool used to extract/dump password hashes for domain users from Active Directory database artifacts (e.g., NTDS.dit and SYSTEM hive).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.