logo

Got Privs? Crack Those Hashes!

ID: bb553521-4e48-5280-a57a-4027212b08e0

STIX ID: report--bb553521-4e48-5280-a57a-4027212b08e0

Feed Name: Black Hills Infosec Blog

Date Published: 2018-05-03

Date Updated: 2026-04-27

Author: BHIS

...
...

This Black Hills InfoSec blog post explains techniques used during penetration tests to obtain Active Directory credential material: it reviews common local privilege escalation vectors, warns about crashing LSASS when dumping hashes, and provides step-by-step guidance to create an IFM backup via NTDSUTIL on a Domain Controller to safely extract NTDS.DIT/SAM/SYSTEM for offline hash extraction and cracking (using Impacket/secretsdump and hashcat), plus cleanup recommendations and a mention of DCSYNC as another approach.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.