Skip to content

Add experimental ntdsdump.py module for OPSEC-safe DCSync#4

Merged
aconite33 merged 1 commit intomasterfrom
ntdsdump
Sep 12, 2025
Merged

Add experimental ntdsdump.py module for OPSEC-safe DCSync#4
aconite33 merged 1 commit intomasterfrom
ntdsdump

Conversation

@Mercury0
Copy link
Copy Markdown

@Mercury0 Mercury0 commented Aug 26, 2025

This PR adds the experimental ntdsdump.py example script which facilitates an offline DCSync using WIN32_ShadowCopy to exfiltrate registry hives and NTDS.dit for local parsing using similar techniques as the current OPSEC-safe SAM dump method.

This module does not activate the remote registry service and therefore has fewer IoCs than a conventional DCSync.

@Mercury0 Mercury0 added the enhancement New feature or request label Aug 26, 2025
@aconite33 aconite33 merged commit 57f6044 into master Sep 12, 2025
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants