sam
Last updated
Last updated
lsadump::sam
dumps the local Security Account Manager (SAM) NT hashes (cf. ). It can operate directly on the target system, or offline with registry hives backups (for SAM
and SYSTEM
). It has the following command line arguments:
/sam
: the offline backup of the SAM hive
/system
: the offline backup of the SYSTEM hive
This command requires elevated privileges (by previously running or by executing Mimikatz as the NT-AUTHORITY\SYSTEM
account).
At first a backup ofSYSTEM
and SAM
hives must be obtained:
A Volume Shadow Copy / BootCD can also be used to backup these files:
Then the saved backups of SYSTEM
and SAM
hives can also be used offline: