Attackers are increasingly targeting Active Directory domain controllers to steal credentials stored in the NTDS.dIT database.