[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fWL1QTa7DlTGkbH3U4PkCLI_brfBQ1duwWQq1naatvSs":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},593,"What are the steps to perform an offline extraction of local user hashes from a Windows system?","First, export the SAM and SYSTEM registry hives using `reg save HKLM\\SYSTEM SystemBkup.hiv` and `reg save HKLM\\SAM SamBkup.hiv` with administrative privileges. Then, on another system, use mimikatz with the command `lsadump::sam \u002Fsam:SamBkup.hiv \u002Fsystem:SystemBkup.hiv` to extract the hashes. Note that the official mimikatz documentation may contain an erroneous syntax; the correct command uses the `\u002Fsam:` and `\u002Fsystem:` parameters. The same technique is described in [Penetration Techniques - Obtaining Local User Hashes via SAM Database](\u002Fnews\u002Fpenetration-techniques-obtaining-local-user-hashes-via-sam-database).","\u003Cp>First, export the SAM and SYSTEM registry hives using `reg save HKLM\\SYSTEM SystemBkup.hiv` and `reg save HKLM\\SAM SamBkup.hiv` with administrative privileges. Then, on another system, use mimikatz with the command `lsadump::sam \u002Fsam:SamBkup.hiv \u002Fsystem:SystemBkup.hiv` to extract the hashes. Note that the official mimikatz documentation may contain an erroneous syntax; the correct command uses the `\u002Fsam:` and `\u002Fsystem:` parameters. The same technique is described in [Penetration Techniques - Obtaining Local User Hashes via SAM Database](\u002Fnews\u002Fpenetration-techniques-obtaining-local-user-hashes-via-sam-database).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-obtaining-local-user-hashes-via-sam-database\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-are-the-steps-to-perform-an-offline-extraction-of-local-user-hashes-from-a--1777482783344","offline extraction, SAM hive, SYSTEM hive, mimikatz, reg save",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},146,"Penetration Techniques - Obtaining Local User Hashes via SAM Database","penetration-techniques-obtaining-local-user-hashes-via-sam-database","Learn techniques to extract local user hashes from Windows SAM database using online and offline methods, including mimikatz and syskey decryption.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>During penetration testing, after gaining access to a Windows system, the sekurlsa::logonpasswords command in mimikatz is typically used to attempt reading the lsass process information to obtain password details of currently logged-in users. However, to comprehensively acquire password information within the system, it is also necessary to extract data stored in the SAM database and export the hashes of all local users in the current system.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Various methods for obtaining user hashes via the SAM database\u003C\u002Fli>\u003Cli>Principle analysis\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Methods for obtaining user hashes via the SAM database\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Online reading of the SAM database\u003C\u002Fh3>\u003Cp>Read the SAM database file of the current system to obtain hashes of all local users\u003C\u002Fp>\u003Ch4>(1) mimikatz\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>privilege::debug\u003Cbr>token::elevate\u003Cbr>lsadump::sam\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017225691_0_75bc69fa8b.png\">\u003C\u002Fp>\u003Ch4>(2) pwdump7\u003C\u002Fh4>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fpasswords.openwall.net\u002Fb\u002Fpwdump\u002Fpwdump7.zip\u003C\u002Fp>\u003Cp>Execute with administrator privileges, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017239663_1_b4a9b20312.png\">\u003C\u002Fp>\u003Ch4>(3) powershell\u003C\u002Fh4>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.com\u002FEmpireProject\u002FEmpire\u002Fmaster\u002Fdata\u002Fmodule_source\u002Fcredentials\u002FInvoke-PowerDump.ps1\u003C\u002Fp>\u003Cp>Execute with administrator privileges, test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017260163_2_feca919433.png\">\u003C\u002Fp>\u003Ch3>2. Offline reading of SAM database\u003C\u002Fh3>\u003Cp>Obtain the SAM database file of the current system and read it on another system.\u003C\u002Fp>\u003Cp>There are two methods to export the SAM database file:\u003C\u002Fp>\u003Ch4>(1) Save the registry\u003C\u002Fh4>\u003Cp>Administrator privileges\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg save HKLM\\SYSTEM SystemBkup.hiv\u003Cbr>reg save HKLM\\SAM SamBkup.hiv\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Copy files\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\System32\\config\\SYSTEM\u003Cbr>C:\\Windows\\System32\\config\\SAM\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Cannot be copied by default, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017286057_3_8b8e2db10a.png\">\u003C\u002Fp>\u003Cp>Requires the use of NinjaCopy, author Joe Bialek, reference download address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>After exporting the SAM database file, on another system, user hashes can be exported in the following ways:\u003C\u002Fp>\u003Ch4>(1) mimikatz\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>lsadump::sam \u002Fsam:SamBkup.hiv \u002Fsystem:SystemBkup.hiv\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017319466_4_40562eb755.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The official documentation of mimikatz has issues, the address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgentilkiwi\u002Fmimikatz\u002Fwiki\u002Fmodule-~-lsadump\u003C\u002Fp>\u003Cp>Export command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>lsadump::sam SystemBkup.hiv SamBkup.hiv\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>will report an error, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017371241_5_bad1509d4b.png\">\u003C\u002Fp>\u003Cp>The available command was provided by @我爱这个世界\u003C\u002Fp>\u003Ch3>Supplement:\u003C\u002Fh3>\u003Cp>The following tools will report errors when reading SAM database files of Win7 systems\u003C\u002Fp>\u003Ch4>(1) Pwdump7\u003C\u002Fh4>\u003Cp>as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017395407_6_5afd0471f1.png\">\u003C\u002Fp>\u003Ch4>(2) Pwdump5\u003C\u002Fh4>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fpasswords.openwall.net\u002Fb\u002Fpwdump\u002Fpwdump5.zip\u003C\u002Fp>\u003Cp>Incorrect read result, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017444774_7_d30aea1f3e.png\">\u003C\u002Fp>\u003Ch4>(3) cain\u003C\u002Fh4>\u003Cp>Test as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017469977_8_173d9deabf.png\">\u003C\u002Fp>\u003Ch2>0x03 Principle Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Read HKLM\\SYSTEM to obtain syskey\u003C\u002Fh3>\u003Cp>Read the contents of keys JD, Skew1, GBG, and Data under registry path HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Lsa, then concatenate them to form syskey\u003C\u002Fp>\u003Cp>Reference code:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fjohannwmeyer\u002Fquarkspwdump\u002Fblob\u002Fa68aa6330f37eb8d00055c73e6a4e3cb52bcdd6d\u002Fsrc\u002Fcrypt.cpp#L222\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgentilkiwi\u002Fmimikatz\u002Fblob\u002Fmaster\u002Fmimikatz\u002Fmodules\u002Fkuhl_m_lsadump.c#L219\u003C\u002Fp>\u003Cp>Complete calculation code can be found at:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.某开源项目.cpp\u003C\u002Fp>\u003Cp>(Steal from http:\u002F\u002Fwww.zcgonvh.com\u002Fpost\u002Fntds_dit_pwd_dumper.html)\u003C\u002Fp>\u003Ch3>2. Use syskey to decrypt HKLM\\SAM\u003C\u002Fh3>\u003Cp>Read the contents of the F and V items for each user under the registry key HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users, and use syskey to perform a series of decryptions\u003C\u002Fp>\u003Cp>Detailed decryption process can be referred to the following link:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.xfocus.net\u002Farticles\u002F200306\u002F550.html\u003C\u002Fp>\u003Cp>In summary, to obtain user hashes via the SAM database, two files are required: HKLM\\SYSTEM and HKLM\\SAM\u003C\u002Fp>\u003Cp>The most direct export method is to read the registry HKLM\\SYSTEM and HKLM\\SAM from the current system, but system privileges are required\u003C\u002Fp>\u003Cp>For methods to switch from admin to system privileges, refer to the previous article: 'Penetration Techniques - Switching from Admin Privileges to System Privileges'\u003C\u002Fp>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces multiple methods to obtain all user hashes via the SAM database, with the key being to read HKLM\\SYSTEM and HKLM\\SAM\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>During penetration testing, after gaining access to a Windows system, the sekurlsa::logonpasswords command in mimikatz is typically used to attempt reading the lsass process information to obtain password details of currently logged-in users. However, to comprehensively acquire password information within the system, it is also necessary to extract data stored in the SAM database and export the hashes of all local users in the current system.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Various methods for obtaining user hashes via the SAM database\u003C\u002Fli>\u003Cli>Principle analysis\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Methods for obtaining user hashes via the SAM database\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Online reading of the SAM database\u003C\u002Fh3>\u003Cp>Read the SAM database file of the current system to obtain hashes of all local users\u003C\u002Fp>\u003Ch4>(1) mimikatz\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>privilege::debug\u003Cbr>token::elevate\u003Cbr>lsadump::sam\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017225691_0_75bc69fa8b-1.png\">\u003C\u002Fp>\u003Ch4>(2) pwdump7\u003C\u002Fh4>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fpasswords.openwall.net\u002Fb\u002Fpwdump\u002Fpwdump7.zip\u003C\u002Fp>\u003Cp>Execute with administrator privileges, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017239663_1_b4a9b20312-1.png\">\u003C\u002Fp>\u003Ch4>(3) powershell\u003C\u002Fh4>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.com\u002FEmpireProject\u002FEmpire\u002Fmaster\u002Fdata\u002Fmodule_source\u002Fcredentials\u002FInvoke-PowerDump.ps1\u003C\u002Fp>\u003Cp>Execute with administrator privileges, test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017260163_2_feca919433-1.png\">\u003C\u002Fp>\u003Ch3>2. Offline reading of SAM database\u003C\u002Fh3>\u003Cp>Obtain the SAM database file of the current system and read it on another system.\u003C\u002Fp>\u003Cp>There are two methods to export the SAM database file:\u003C\u002Fp>\u003Ch4>(1) Save the registry\u003C\u002Fh4>\u003Cp>Administrator privileges\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg save HKLM\\SYSTEM SystemBkup.hiv\u003Cbr>reg save HKLM\\SAM SamBkup.hiv\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Copy files\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\System32\\config\\SYSTEM\u003Cbr>C:\\Windows\\System32\\config\\SAM\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Cannot be copied by default, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017286057_3_8b8e2db10a-1.png\">\u003C\u002Fp>\u003Cp>Requires the use of NinjaCopy, author Joe Bialek, reference download address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>After exporting the SAM database file, on another system, user hashes can be exported in the following ways:\u003C\u002Fp>\u003Ch4>(1) mimikatz\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>lsadump::sam \u002Fsam:SamBkup.hiv \u002Fsystem:SystemBkup.hiv\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017319466_4_40562eb755-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The official documentation of mimikatz has issues, the address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgentilkiwi\u002Fmimikatz\u002Fwiki\u002Fmodule-~-lsadump\u003C\u002Fp>\u003Cp>Export command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>lsadump::sam SystemBkup.hiv SamBkup.hiv\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>will report an error, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017371241_5_bad1509d4b-1.png\">\u003C\u002Fp>\u003Cp>The available command was provided by @我爱这个世界\u003C\u002Fp>\u003Ch3>Supplement:\u003C\u002Fh3>\u003Cp>The following tools will report errors when reading SAM database files of Win7 systems\u003C\u002Fp>\u003Ch4>(1) Pwdump7\u003C\u002Fh4>\u003Cp>as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017395407_6_5afd0471f1-1.png\">\u003C\u002Fp>\u003Ch4>(2) Pwdump5\u003C\u002Fh4>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fpasswords.openwall.net\u002Fb\u002Fpwdump\u002Fpwdump5.zip\u003C\u002Fp>\u003Cp>Incorrect read result, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017444774_7_d30aea1f3e-1.png\">\u003C\u002Fp>\u003Ch4>(3) cain\u003C\u002Fh4>\u003Cp>Test as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017469977_8_173d9deabf-1.png\">\u003C\u002Fp>\u003Ch2>0x03 Principle Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Read HKLM\\SYSTEM to obtain syskey\u003C\u002Fh3>\u003Cp>Read the contents of keys JD, Skew1, GBG, and Data under registry path HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Lsa, then concatenate them to form syskey\u003C\u002Fp>\u003Cp>Reference code:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fjohannwmeyer\u002Fquarkspwdump\u002Fblob\u002Fa68aa6330f37eb8d00055c73e6a4e3cb52bcdd6d\u002Fsrc\u002Fcrypt.cpp#L222\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgentilkiwi\u002Fmimikatz\u002Fblob\u002Fmaster\u002Fmimikatz\u002Fmodules\u002Fkuhl_m_lsadump.c#L219\u003C\u002Fp>\u003Cp>Complete calculation code can be found at:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.某开源项目.cpp\u003C\u002Fp>\u003Cp>(Steal from http:\u002F\u002Fwww.zcgonvh.com\u002Fpost\u002Fntds_dit_pwd_dumper.html)\u003C\u002Fp>\u003Ch3>2. Use syskey to decrypt HKLM\\SAM\u003C\u002Fh3>\u003Cp>Read the contents of the F and V items for each user under the registry key HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users, and use syskey to perform a series of decryptions\u003C\u002Fp>\u003Cp>Detailed decryption process can be referred to the following link:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.xfocus.net\u002Farticles\u002F200306\u002F550.html\u003C\u002Fp>\u003Cp>In summary, to obtain user hashes via the SAM database, two files are required: HKLM\\SYSTEM and HKLM\\SAM\u003C\u002Fp>\u003Cp>The most direct export method is to read the registry HKLM\\SYSTEM and HKLM\\SAM from the current system, but system privileges are required\u003C\u002Fp>\u003Cp>For methods to switch from admin to system privileges, refer to the previous article: 'Penetration Techniques - Switching from Admin Privileges to System Privileges'\u003C\u002Fp>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces multiple methods to obtain all user hashes via the SAM database, with the key being to read HKLM\\SYSTEM and HKLM\\SAM\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",939,"Onedaysec",3,"published","2026-02-02T07:38:21.455Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Windows Penetration: Extracting Local User Hashes from SAM Database","SAM database, user hashes, Windows penetration, mimikatz, pwdump7, offline reading, syskey decryption",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4,47],596,595,594,592,{"title":39,"description":39,"image":39},"2026-07-24T15:37:12.504Z","2026-07-23T16:01:48.946Z","draft","2026-07-23T16:13:37.534Z"]