The File That Turns One Windows Breach Into Every Password in the Domain
One file on a Windows domain controller can contain password hashes, Kerberos keys and password history for every account in the domain. Steal it with the matching SYSTEM registry hive and a local compromise can become a durable identity crisis.
Trellix has published a controlled simulation of that path, from an initial foothold through credential collection, lateral movement, Volume Shadow Copy abuse and HTTPS exfiltration. It is not a report of a newly discovered victim or a claim that one named group used this exact sequence. The useful part is the sequence itself.
Why NTDS.dit changes the recovery problem
The Active Directory database is normally locked while the domain controller is running. In the simulation, the attacker used Volume Shadow Copy Service to create a readable copy, then exported the SYSTEM hive containing the material needed to decrypt it offline.
The result is not simply a list of passwords. NTLM hashes can support pass-the-hash activity without recovering the original password. Kerberos material can help an intruder forge tickets. Access to the KRBTGT secret can make a Golden Ticket possible, allowing the attacker to manufacture authentication claims that survive a partial cleanup.
Deleting the original malware therefore does not finish the response. Defenders have to determine which credentials were exposed, where those credentials were reused, whether forged tickets were issued and whether the directory database left the network.
The chain produces behaviour worth detecting
- Unexpected shadow-copy creation on or against a domain controller.
- Collection of
ntds.ditand the SYSTEM hive, particularly into staging directories. - Administrative SMB activity and remote service execution reaching a domain controller from an unusual host.
- Large or unfamiliar outbound HTTPS transfers originating from identity infrastructure.
- Credential access involving LSASS followed by rapid movement towards directory services.
- DCSync activity from systems or accounts that do not normally perform replication.
No single event proves theft. A legitimate administrator can create a snapshot, and backup software can read sensitive files. The strongest signal is correlation: unusual privilege escalation, shadow-copy activity, directory-file access and outbound transfer within the same incident window.
If the database may have left, respond as an identity breach
- Isolate affected systems while preserving memory, event logs and network evidence.
- Reset exposed privileged and service accounts in a controlled order.
- Plan the Microsoft-recommended double rotation of KRBTGT rather than changing it casually during an unstable incident.
- Audit replication rights, privileged groups, new trusts, scheduled tasks and remote-management paths.
- Reduce or remove NTLM where operationally possible and place suitable administrators in Protected Users.
- Restrict outbound web access and unnecessary SMB paths from domain controllers.
The lesson is not that every attack uses Meterpreter or one named dumping tool. It is that the directory is the prize, native Windows mechanisms can help reach it, and defenders need controls that recognise the technique even when the executable changes.
Sources
- Trellix Advanced Research Center simulation and detection report, published in September 2026.
- Cyber Security News coverage, published 22 September 2026.


