mirror of
				https://github.com/LOLBAS-Project/LOLBAS
				synced 2025-11-04 02:29:34 +01:00 
			
		
		
		
	Update Dsdbutil.yml
This commit is contained in:
		@@ -11,28 +11,28 @@ Commands:
 | 
			
		||||
    Usecase: Snapshoting of Active Directory NTDS.dit database
 | 
			
		||||
    Category: Dump
 | 
			
		||||
    Privileges: Administrator
 | 
			
		||||
    MitreID: T1003.003: NTDS
 | 
			
		||||
    MitreID: T1003.003
 | 
			
		||||
    OperatingSystem: Windows Server 2012, Windows Server 2016, Windows Server 2019
 | 
			
		||||
  - Command: dsdbutil.exe "activate instance ntds" "snapshot" "mount {GUID}" "quit" "quit"
 | 
			
		||||
    Description: Mounting the snapshot with its GUID
 | 
			
		||||
    Usecase: Mounting the snapshot to access the ntds.dit with copy c:\[Snap Volume]\windows\ntds\ntds.dit c:\users\administrator\desktop\ntds.dit.bak
 | 
			
		||||
    Category: Dump
 | 
			
		||||
    Privileges: Administrator
 | 
			
		||||
    MitreID: T1003.003: NTDS
 | 
			
		||||
    MitreID: T1003.003
 | 
			
		||||
    OperatingSystem: Windows Server 2012, Windows Server 2016, Windows Server 2019
 | 
			
		||||
  - Command: dsdbutil.exe "activate instance ntds" "snapshot" "delete {GUID}" "quit" "quit"
 | 
			
		||||
    Description: Deletes the mount of the snapshot
 | 
			
		||||
    Usecase: Deletes the snapshot
 | 
			
		||||
    Category: Dump
 | 
			
		||||
    Privileges: Administrator
 | 
			
		||||
    MitreID: T1003.003: NTDS
 | 
			
		||||
    MitreID: T1003.003
 | 
			
		||||
    OperatingSystem: Windows Server 2012, Windows Server 2016, Windows Server 2019
 | 
			
		||||
  - Command: dsdbutil.exe "activate instance ntds" "snapshot" "create" "list all" "mount 1" "quit" "quit"
 | 
			
		||||
    Description: Mounting with snapshot identifier
 | 
			
		||||
    Usecase: Mounting the snapshot identifier 1 and accessing it with with copy c:\[Snap Volume]\windows\ntds\ntds.dit c:\users\administrator\desktop\ntds.dit.bak
 | 
			
		||||
    Category: Dump
 | 
			
		||||
    Privileges: Administrator
 | 
			
		||||
    MitreID: T1003.003: NTDS
 | 
			
		||||
    MitreID: T1003.003
 | 
			
		||||
    OperatingSystem: Windows Server 2012, Windows Server 2016, Windows Server 2019
 | 
			
		||||
  - Command: dsdbutil.exe "activate instance ntds" "snapshot" "list all" "delete 1" "quit" "quit"
 | 
			
		||||
    Description: Deletes the mount of the snapshot
 | 
			
		||||
 
 | 
			
		||||
		Reference in New Issue
	
	Block a user