NTDS.dit

  • Main AD database file on Domain Controllers.

  • Contains:

    • Usernames

    • Group info

    • Password hashes

  • Default location: C:\Windows\NTDS\NTDS.dit

  • If extracted, it can be used to dump credentials offline.