Impacket NTFS-Read (Offline NTDS Browse)

Browse a raw NTFS image (e.g. a VSS shadow copy of C:\Windows\NTDS) offline as if it were a filesystem. Use to extract NTDS.dit + SYSTEM hive after dumping a shadow copy when secretsdump direct methods are blocked.

Tool
impacket-ntfs-read
Category
Post-Exploitation / Data Collection
Platform
linux
Requires
no credentials

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

impacket-ntfs-read <ntds_image_or_vss_dump>

Examples

impacket-ntfs-read shadowcopy.dd
# inside the interactive shell:
use 1
cd Windows\NTDS
get NTDS.dit

Tags

impacket ntfs offline ntds vss shadow-copy

References