Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as devices, users, and access rights.
Tactics
TA0006
Sub-technique of
T1003
See: MITRE ATT&CK