.. / AD - ntdsutil.exe - Dump DC hashes without password

If you have no credentials, but you have access to the DC, it’s possible to dump the ntds.dit using ntdsutil.exe. The ntds.dit and SYSTEM as well as SECURITY registry hives are dumped to c:\temp.

Command: Copy References:

https://www.ired.team/offensive-security/credential-access-and-credential-dumping/ntds.dit-enumeration