SeBackupPrivilege
This privilege is a win. We can create a shadow copy of the OS and read secret files such as SYSTEM, SECURITY, NTDS.dit etc
Create a shadow copy and expose it as a network share.
Diskshadow.exe puts you into an interactive session so If the commands above doesn't work, don't forget to add ; after the commands.
To abuse my SeBackupPrivilege privilege, use the dll below and enable your privilege.
After that you can copy the secret files,
And you can dump the hashes locally
Last updated