Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Feature to extract Ntds.dit without touching disk? #3

Open
RogueThread opened this issue Aug 5, 2024 · 1 comment
Open

Feature to extract Ntds.dit without touching disk? #3

RogueThread opened this issue Aug 5, 2024 · 1 comment

Comments

@RogueThread
Copy link

Could this be implemented?

@jfjallid
Copy link
Owner

jfjallid commented Aug 5, 2024

As far as I know, ntds.dit is not mapped to the windows registry so dumping that file is a bit out of scope for this tool.

The technique that comes to mind to dump the credentials without touching disk would be a dcsync which might be exposed via IPC (haven't checked).
I might take a look at that later and consider expanding the scope of this tool.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants