ESENT › Event 327

Event ID 327 —

Provider
ESENT
Channel
Application
Level
Informational
Collection Priority
Recommended (ASD)

Fields #

NameDescription
Data

Example Event #

{
  "system": {
    "provider": "ESENT",
    "guid": "",
    "event_source_name": "",
    "event_id": 327,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2021-06-05T19:36:58.926651+00:00",
    "event_record_id": 442152,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "rootdc1.offsec.lan",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "NTDS",
      "7148",
      "",
      "1",
      "C:\\$SNAP_202106051936_VOLUMEC$\\Windows\\NTDS\\ntds.dit",
      "0",
      "[1] 0.000, [2] 0.000, [3] 0.000, [4] 0.000, [5] 0.000, [6] 0.016, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000, [11] 0.000, [12] 0.000.",
      "0 0"
    ]
  },
  "message": ""
}

Detection Patterns #

Credential Access: NTDS

1 rule

Sigma

Nasreddine Bencherchali (Nextron Systems)

References #