A VMware guest's disk is a VMDK pair (a small descriptor and a large -flat or sparse extent) on a VMFS or NFS datastore. With ESXi shell, API, or storage access, copying the VMDK and mounting it offline exposes the guest filesystem and its secrets, or the whole VM can be registered and booted on attacker infrastructure.
# On the ESXi host: locate and export a guest disk
ls /vmfs/volumes/<datastore>/<vm>/
# Download via the datastore browser (vSphere API) or scp, then mount offline:
qemu-nbd -r -c /dev/nbd0 vm-flat.vmdk && mount -o ro /dev/nbd0p1 /mnt
# Extract SAM/SYSTEM or NTDS.dit from the mounted volume
Exploitation notes#
- Offline access sidesteps the guest OS: pull
SAM/SYSTEM, orNTDS.ditfrom a domain controller VM, then crack or pass the hashes. - Snapshots (
-delta.vmdk) capture point-in-time state and memory (.vmsn/.vmem), which can hold live secrets. - Thin extents may need consolidation;
vmkfstools -ion the host clones a VMDK into a portable image.