A Hyper-V guest's disk is a VHD/VHDX file, and each checkpoint adds an AVHDX differencing file. With host or share access, copying these and mounting them offline exposes the guest filesystem, including credential stores, with no need to boot or authenticate to the guest.
Get-VMHardDiskDrive -VMName <guest> # find the disk paths
Copy-Item '\\host\c$\...\guest.vhdx' .\loot.vhdx # exfiltrate
Mount-VHD -Path .\loot.vhdx -ReadOnly # mount offline
# Then extract SAM/SYSTEM or NTDS.dit from the mounted volume
Exploitation notes#
- Offline disk access sidesteps the guest OS entirely: pull
SAM/SYSTEMfrom a member, orNTDS.ditfrom a domain controller VM, then crack or pass the hashes. - Standard checkpoints capture point-in-time state including memory (
.vmrs/.bin), which can hold secrets from a running guest; production checkpoints (the default on current Hyper-V) are application-consistent and disk-only, so they do not. - A mounted disk is also a write primitive: plant a payload or clear a password before the guest next boots.