logo

Juicing ntds.dit Files to the Last Drop

ID: 1edf625d-334d-5df1-9e76-cfc84facd9cb

STIX ID: report--1edf625d-334d-5df1-9e76-cfc84facd9cb

Feed Name: SpecterOps Blog

Date Published: 2025-08-14

Date Updated: 2026-04-30

Author: Michael Grafnetter

...
...

This article details new DSInternals PowerShell capabilities for offline Active Directory data access and attack support, including Golden gMSA/dMSA password derivation via KDS root keys, full Windows LAPS password decryption (including histories and DSRM), extraction of trust passwords with Kerberos key derivation for ticket attacks, retrieval of BitLocker recovery keys, support for RODC databases, and significant performance improvements; it also underscores security, compliance, and detection considerations around handling ntds.dit.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.