deployment-mdt.md (3213B)
1 --- 2 title: "Deployment - MDT" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/deployment-mdt.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/deployment-mdt.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Deployment - MDT 12 13 Microsoft Deployment Toolkit (MDT) is a free tool from Microsoft used to automate the deployment of Windows operating systems and applications. 14 15 It lets IT admins create a central deployment share with OS images, drivers, updates, and apps, then use automated scripts (task sequences) to install them on multiple computers, either over the network (Lite Touch) or from media (USB/DVD). 16 17 ## Deployment Share 18 19 These files contains credentials used by Microsoft Deployment Toolkit to join a computer to the domain and to access network resources. 20 21 * **Bootstrap.ini** - Located in `DeploymentShare\Control\Bootstrap.ini` 22 * **CustomSettings.ini** - Located in `DeploymentShare\Control\CustomSettings.ini` 23 24 | Name | Description | 25 | ---------------------------- | ------------------------------------------------------------------ | 26 | DomainAdmin | Account used to join the computer to the domain | 27 | DomainAdminPassword | Password used to join the computer to the domain | 28 | UserID | Account used for accessing network resources | 29 | UserPassword | Password used for accessing network resources | 30 | AdminPassword | The local administrator account on the computer | 31 | ADDSUserName | Account used when promoting to DC during deployment | 32 | ADDSPassword | Password used when promoting to DC during deployment | 33 | Password | Password to use for promoting member server to a domain controller | 34 | SafeModeAdminPassword | Used when deploying DCs, it is the AD restore mode password | 35 | TPMOwnerPassword | The TPM password if not set already | 36 | DBID | Account used to connect to SQL server during deployment | 37 | DBPwd | Password used to connect to SQL server during deployment | 38 | OSDBitLockerRecoveryPassword | BitLocker recovery password | 39 40 Other credentials can be found inside the files hosted in the deployment share: 41 42 * `DeploymentShare\Control\TASKSEQUENCENAME\ts.xml` 43 * `DeploymentShare\Scripts\` folder 44 * `DeploymentShare\Applications` folder 45 * `LiteTouchPE_x86|x64.iso`, extract files and look for `bootstrap.ini` 46 * `LiteTouchPE_x86|x64.wim`, extract files and look for `bootstrap.ini` 47 48 ## References 49 50 * [Red Team Gold: Extracting Credentials from MDT Shares - Oddvar Moe - May 20, 2025](https://trustedsec.com/blog/red-team-gold-extracting-credentials-from-mdt-shares) 51 * [MDT, where are you? - BlackWasp - June 27, 2025](https://hideandsec.sh/books/windows-sNL/page/mdt-where-are-you)