Getting Started with WMI Weaponization – Part 4
netspi.com | blog | #active-directory | #wmi | #ntds-dit | #credential-dumping | #volume-shadow-copy
Summary
Replicates ntds.dit dumping with pure WMI Win32_ShadowCopy calls instead of vssadmin, remotely snapshotting a domain controller to pull password hashes while trimming the tool-based IoC footprint.
- Published
- Collected
Skip to content