Sub-technique of T1003 OS Credential Dumping.View on attack.mitre.org
Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as devices, users, and access rights. By default, the NTDS file (NTDS.dit) is located in %SystemRoot%\NTDS\Ntds.dit of a domain controller.
In addition to looking for NTDS files on active Domain Controllers, adversaries may search for backups that contain the same or similar information.
The following tools and techniques can be used to enumerate the NTDS file and the contents of the entire Active Directory hashes.
* Volume Shadow Copy
* secretsdump.py
* Using the in-built Windows tool, ntdsutil.exe
* Invoke-NinjaCopy
Rules on DetectionCode tagged with T1003.003.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Creation of Shadow Copy | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Creation of Shadow Copy with wmic and powershell | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Credential Dumping via Copy Command from Shadow Copy | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Credential Dumping via Symlink to Shadow Copy | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Ntdsutil Export NTDS | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| SecretDumps Offline NTDS Dumping Tool | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Used by | Procedure example |
|---|---|
| GroupAPT28 | APT28 has used the ntdsutil.exe utility to export the Active Directory database for credential access. |
| GroupAPT41 | APT41 used ntdsutil to obtain a copy of the victim environment |
| GroupChimera | Chimera has gathered the SYSTEM registry and ntds.dit files from target systems. Chimera specifically has used the NtdsAudit tool to dump the password hashes of domain users via |
| GroupDragonfly | Dragonfly has dropped and executed SecretsDump to dump password hashes. They also obtained ntds.dit from domain controllers. |
| GroupFIN13 | FIN13 has harvested the NTDS.DIT file and leveraged the Impacket tool on the compromised domain controller to locally decrypt it. |
| GroupFIN6 | FIN6 has used Metasploit’s PsExec NTDSGRAB module to obtain a copy of the victim's Active Directory database. |
| GroupFox Kitten | Fox Kitten has used Volume Shadow Copy to access credential information from NTDS. |
| GroupHAFNIUM | HAFNIUM has stolen copies of the Active Directory database (NTDS.DIT). |
| Used by | Procedure example |
|---|---|
| ToolCrackMapExec | CrackMapExec can dump hashed passwords associated with Active Directory using Windows' Directory Replication Services API (DRSUAPI), or Volume Shadow Copy. |
| Toolesentutl | esentutl can copy `ntds.dit` using the Volume Shadow Copy service. |
| ToolImpacket | SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information from NTDS.dit. |
| ToolKoadic | Koadic can gather hashed passwords by gathering domain controller hashes from NTDS. |
| Used by | Procedure example |
|---|---|
| Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries dumped the entire Active Directory database by extracting the contents of the ntds.dit file. |
| CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 dumped NTDS.dit through creating volume shadow copies via |
| CampaignCutting Edge | During Cutting Edge, threat actors accessed and mounted virtual hard disk backups to extract |
| CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors obtained active directory credentials via the NTDS.DIT file. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.