#Windows Security #Domain Privesc #Credentials Dump #Local SAM
Credentials dump from local SAM
Requirements:
- You have to be a local administrator on the machine (or SYSTEM).
SAM dump will return all local users on the system along with their hashed passwords in NT hash form.
Windows:
Linux:
Offline SAM database dump
You can also steal SAM database file and SYSTEM registry hive and extract credentials offline:
- SAM:
C:\Windows\System32\config\SAM
- SYSTEM:
C:\Windows\System32\config\SYSTEM