In order to retrieve NTDS.dir, attacker need access to either local admin account or domain administrator account.
- Create Shadow copy of C:
NTDS.dit is most likely to be stored on C: drive.
- Copy NTDS.dit from VSS
Copy NTDS.dir from the volume shadow copy of C: onto another location on the drive.
- Transfer NTDS.dit to attacker machine.
CME
Using CME can make this process much faster.