Skip to content
This repository was archived by the owner on Dec 11, 2018. It is now read-only.

Latest commit

 

History

History
33 lines (22 loc) · 720 Bytes

Diskshadow.md

File metadata and controls

33 lines (22 loc) · 720 Bytes

UPDATE BOOKMARKS - PROJECT MOVED TO A DEDICATED PROJECT SITE. THIS SITE WILL NOT BE UPDATED ANYMORE, BUT WILL BE KEPT FOR HISTORICAL REASONS.

New site: https://github.com/LOLBAS-Project/LOLBAS Web portal: https://lolbas-project.github.io/

Diskshadow.exe

  • Functions: Execute, Dump NTDS.dit
diskshadow.exe /s c:\test\diskshadow.txt   

diskshadow> exec calc.exe    

Acknowledgements:

  • Jimmy - @bohops

Code sample: *

Resources:

Full path:

c:\windows\system32\diskshadow.exe
c:\windows\sysWOW64\diskshadow.exe

Notes: Only present on Windows Server OS 2008 and newer