shadowcopies

misc::shadowcopies is used to list the available shadow copies on the system.

The hivenightmare/serious sam vulnerability was discovered by JonasLykarrow-up-right. According to Will Dormannarrow-up-right,Builtin\Users had RX access to the SAM, somewhere between Windows 10 1803 and 1809, hence allowing regular users to operate SAM dumpingarrow-up-right.

Win10 1809 SAM file ACLs
Win10 1090 SAM file ACLs
Win 10.0.19043.1110 (21H1) SAM file ACLs

The then lsadump::sam can be used by defining the shadow copies paths for /sam and /system.

Last updated