Impacket NTFS-Read (Offline NTDS Browse)
Browse a raw NTFS image (e.g. a VSS shadow copy of C:\Windows\NTDS) offline as if it were a filesystem. Use to extract NTDS.dit + SYSTEM hive after dumping a shadow copy when secretsdump direct methods are blocked.
- Tool
- impacket-ntfs-read
- Category
- Post-Exploitation / Data Collection
- Platform
- linux
- Requires
- no credentials
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
impacket-ntfs-read <ntds_image_or_vss_dump>
Examples
impacket-ntfs-read shadowcopy.dd
# inside the interactive shell:
use 1
cd Windows\NTDS
get NTDS.dit
Tags
References
Related commands
- NetExec RDP Screenshot Capture a screenshot of the current RDP login screen / desktop without authenticating…
- NetExec SMB BitLocker Recovery Keys Retrieve BitLocker recovery keys stored in Active Directory
- NetExec WMI bitlocker Module Pull BitLocker recovery keys from a host over WMI. Faster than the SMB equivalent in…
- SMBClient Recursive Download Download folder recursively from SMB share