SAM SYSTEM Exfil / Pass The Hash
We then proceed to make a backup of
SAM
andSYSTEM
files and download them to our attacker machine:
With those files, we can dump the password hashes for all users using secretsdump.py or other similar tools:
And finally, perform Pass-the-Hash to connect to the victim machine with Administrator privileges:
Last updated