NTDS.dit Extraction
Recovering the Active Directory database file, which holds every domain account's password hash, typically via a Volume Shadow Copy of the domain controller's system volume.
NTDS.dit is the Active Directory database on every domain controller —
a single file containing the password hash of every domain account, not just
one host's local users. It is permanently locked by the running directory
service, so it cannot be copied like an ordinary file; recovering it requires
either a domain controller's own replication protocol or a filesystem-level
trick that bypasses the lock entirely.
How it works
The most common path takes a Volume Shadow Copy of the volume holding
NTDS.dit, which freezes a point-in-time, unlocked view of the filesystem
that ordinary file APIs can then read from:
vssadmin create shadow /for=C:
copy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\Windows\NTDS\NTDS.dit .
reg.exe save HKLM\SYSTEM system.hiv ; boot key, needed to decrypt NTDS.ditA second path abuses the domain controller's own DRS (Directory Replication Service) RPC interface to request password data as if the attacker's machine were another domain controller synchronising via normal replication (colloquially "DCSync") — this needs no file access at all, only replication-equivalent AD rights, and produces the same hash material directly over the network.
Detection & analysis
- Static — Scripts or tools invoking
vssadmin create shadowfollowed by a copy from aHarddiskVolumeShadowCopydevice path targetingNTDS.ditare an unambiguous static/behavioural signature. - Dynamic — Event ID 8222 (VSS) for unexpected shadow-copy creation
outside a backup window; file reads of
NTDS.ditby any process other thanlsass.exe/backup software; for the DCSync path, Event ID 4662 with theDS-Replication-Get-Changes/-Allextended rights on an account that is not a domain controller computer object is the canonical detection — this event exists specifically because DCSync abuses a legitimate, auditable AD permission rather than a bug. - Scope — Because NTDS.dit yields every domain account's hash in one step, this is one of the highest-impact credential-access techniques an incident responder can face — treat its confirmed use as a full domain compromise requiring a company-wide credential reset, not a single-host incident.
- Tools — Impacket's
secretsdump.py(both-use-vssandDRSUAPI/ DCSync modes) for understanding the offline analysis side, Microsoft's own Advanced Threat Analytics / Defender for Identity for DCSync detection, Sysmon + Windows Security auditing for the VSS and Event ID 4662 signals.