NTDS

T1003.003

Sub-technique of T1003 OS Credential Dumping.View on attack.mitre.org

About this technique

Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as devices, users, and access rights. By default, the NTDS file (NTDS.dit) is located in %SystemRoot%\NTDS\Ntds.dit of a domain controller.

In addition to looking for NTDS files on active Domain Controllers, adversaries may search for backups that contain the same or similar information.

The following tools and techniques can be used to enumerate the NTDS file and the contents of the entire Active Directory hashes.

* Volume Shadow Copy
* secretsdump.py
* Using the in-built Windows tool, ntdsutil.exe
* Invoke-NinjaCopy

Detection rules29

Rules on DetectionCode tagged with T1003.003.

Sigma23

RuleLevelLog source
Copying Sensitive Files with Credential Datahighwindows / process_creation
Create Volume Shadow Copy with Powershellhighwindows / ps_script
Cred Dump Tools Dropped Fileshighwindows / file_event
NTDS Exfiltration Filename Patternshighwindows / file_event
NTDS.DIT Creation By Uncommon Parent Processhighwindows / file_event
NTDS.DIT Creation By Uncommon Processhighwindows / file_event
Possible Impacket SecretDump Remote Activityhighwindows / NULL
Possible Impacket SecretDump Remote Activity - Zeekhighzeek / NULL
PUA - DIT Snapshot Viewerhighwindows / process_creation
Sensitive File Dump Via Print.EXEhighwindows / process_creation
Sensitive File Dump Via Wbadmin.EXEhighwindows / process_creation
Sensitive File Recovery From Backup Via Wbadmin.EXEhighwindows / process_creation
Suspicious Get-ADDBAccount Usagehighwindows / ps_module
Suspicious Process Patterns NTDS.DIT Exfilhighwindows / process_creation
VolumeShadowCopy Symlink Creation Via Mklinkhighwindows / process_creation

Splunk6

RuleTypeRiskData source
Creation of Shadow CopyTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Creation of Shadow Copy with wmic and powershellTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Credential Dumping via Copy Command from Shadow CopyTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Credential Dumping via Symlink to Shadow CopyTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Ntdsutil Export NTDSTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
SecretDumps Offline NTDS Dumping ToolTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups18

Software4

Campaigns4

Procedure examples26

Groups18

Used byProcedure example
GroupAPT28

APT28 has used the ntdsutil.exe utility to export the Active Directory database for credential access.

GroupAPT41

APT41 used ntdsutil to obtain a copy of the victim environment ntds.dit file.

GroupChimera

Chimera has gathered the SYSTEM registry and ntds.dit files from target systems. Chimera specifically has used the NtdsAudit tool to dump the password hashes of domain users via msadcs.exe "NTDS.dit" -s "SYSTEM" -p RecordedTV_pdmp.txt --users-csv RecordedTV_users.csv and used ntdsutil to copy the Active Directory database.

GroupDragonfly

Dragonfly has dropped and executed SecretsDump to dump password hashes. They also obtained ntds.dit from domain controllers.

GroupFIN13

FIN13 has harvested the NTDS.DIT file and leveraged the Impacket tool on the compromised domain controller to locally decrypt it.

GroupFIN6

FIN6 has used Metasploit’s PsExec NTDSGRAB module to obtain a copy of the victim's Active Directory database.

GroupFox Kitten

Fox Kitten has used Volume Shadow Copy to access credential information from NTDS.

GroupHAFNIUM

HAFNIUM has stolen copies of the Active Directory database (NTDS.DIT).

View all 18 groups examples

Software4

Used byProcedure example
ToolCrackMapExec

CrackMapExec can dump hashed passwords associated with Active Directory using Windows' Directory Replication Services API (DRSUAPI), or Volume Shadow Copy.

Toolesentutl

esentutl can copy `ntds.dit` using the Volume Shadow Copy service.

ToolImpacket

SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information from NTDS.dit.

ToolKoadic

Koadic can gather hashed passwords by gathering domain controller hashes from NTDS.

Campaigns4

Used byProcedure example
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries dumped the entire Active Directory database by extracting the contents of the ntds.dit file.

CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 dumped NTDS.dit through creating volume shadow copies via vssadmin.

CampaignCutting Edge

During Cutting Edge, threat actors accessed and mounted virtual hard disk backups to extract
ntds.dit.

CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors obtained active directory credentials via the NTDS.DIT file.

References2

  1. Metcalf 2015 Open source
    Metcalf, S. (2015, January 19). Attackers Can Now Use Mimikatz to Implant Skeleton Key on Domain Controllers & BackDoor Your Active Directory Forest. Retrieved February 3, 2015.
  2. Wikipedia Active Directory Open source
    Wikipedia. (2018, March 10). Active Directory. Retrieved April 11, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.