logo

Offline Memory Forensics With Volatility

ID: 9433b24d-4ce4-5308-9eec-058929a8f0b8

STIX ID: report--9433b24d-4ce4-5308-9eec-058929a8f0b8

Feed Name: Black Hills Infosec Blog

Threat Score
60/100

Date Published: 2025-04-08

Date Updated: 2026-04-27

Author: BHIS

...
...

**Executive Summary:** This article demonstrates a practical technique for extracting Windows SAM hashes from an ESXi VM memory snapshot using Volatility, then relaying those hashes to obtain local and domain credentials; it walks through taking a snapshot with memory included, downloading the vmem file, running Volatility commands to dump SAM hashes, and using pass-the-hash/relay tools to escalate to domain accounts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.