Skip to content

NTDS.dit Extraction

Recovering the Active Directory database file, which holds every domain account's password hash, typically via a Volume Shadow Copy of the domain controller's system volume.

NTDS.dit is the Active Directory database on every domain controller — a single file containing the password hash of every domain account, not just one host's local users. It is permanently locked by the running directory service, so it cannot be copied like an ordinary file; recovering it requires either a domain controller's own replication protocol or a filesystem-level trick that bypasses the lock entirely.

How it works

The most common path takes a Volume Shadow Copy of the volume holding NTDS.dit, which freezes a point-in-time, unlocked view of the filesystem that ordinary file APIs can then read from:

text
vssadmin create shadow /for=C:
copy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\Windows\NTDS\NTDS.dit .
reg.exe save HKLM\SYSTEM system.hiv     ; boot key, needed to decrypt NTDS.dit

A second path abuses the domain controller's own DRS (Directory Replication Service) RPC interface to request password data as if the attacker's machine were another domain controller synchronising via normal replication (colloquially "DCSync") — this needs no file access at all, only replication-equivalent AD rights, and produces the same hash material directly over the network.

Detection & analysis

  • Static — Scripts or tools invoking vssadmin create shadow followed by a copy from a HarddiskVolumeShadowCopy device path targeting NTDS.dit are an unambiguous static/behavioural signature.
  • Dynamic — Event ID 8222 (VSS) for unexpected shadow-copy creation outside a backup window; file reads of NTDS.dit by any process other than lsass.exe/backup software; for the DCSync path, Event ID 4662 with the DS-Replication-Get-Changes/-All extended rights on an account that is not a domain controller computer object is the canonical detection — this event exists specifically because DCSync abuses a legitimate, auditable AD permission rather than a bug.
  • Scope — Because NTDS.dit yields every domain account's hash in one step, this is one of the highest-impact credential-access techniques an incident responder can face — treat its confirmed use as a full domain compromise requiring a company-wide credential reset, not a single-host incident.
  • Tools — Impacket's secretsdump.py (both -use-vss and DRSUAPI/ DCSync modes) for understanding the offline analysis side, Microsoft's own Advanced Threat Analytics / Defender for Identity for DCSync detection, Sysmon + Windows Security auditing for the VSS and Event ID 4662 signals.
Votes

Comments(0)