LOLBAS/OSBinaries/Diskshadow.md

478 B

Diskshadow.exe

  • Functions: Execute, Dump NTDS.dit
diskshadow.exe /s c:\test\diskshadow.txt   

diskshadow> exec calc.exe    

Acknowledgements:

  • Jimmy - @bohops

Code sample: *

Resources:

Full path:

c:\windows\system32\diskshadow.exe
c:\windows\sysWOW64\diskshadow.exe

Notes: Only present on Windows Server OS 2008 and newer