SAM & LSA secrets

Shadow Copies / Snapshots
Enumerate the host for shadow copy volumes
Step by step - Manual
Over SMB - Automation
SAM
Registry Hive
Description
Windows
Transfer files
Download - Exfiltrationesentutl.exe
Secretsdump

Metasploit
MetasploitNetexec - CME
NetExec - CMELocal admin
Mimikatz
MimikatzSilentSAM
SAMDump
SharpSAMDump
CVE-2025-33073 - NTLM Reflection
Cracking
HashesOnline
Pass the Hash (PtH)
Pass the Hash (PtH)LSA
Netexec - CME
NetExec - CMEGMSA
regsecrets.py
Bypass LSA Protection (aka Protected Process Light)
Backup Operators Group
Group PrivilegesLinux
Windows
Go-Secdump
Volatility3 - Hashdump
Dump memory acquisition from victim host - With WinPmem or FTK Imager
Hashdump / Lsadump
Resources
Interesting Book
Interesting BooksSupport this Gitbook
Last updated


