Dumping LSA secrets: a story about task decorrelation
ID: fbac8c6c-8dbb-5f91-8521-748ec4fac296
STIX ID: report--fbac8c6c-8dbb-5f91-8521-748ec4fac296
Feed Name: SensePost Blog
The report details a practical method to bypass EDR controls and dump Windows LSA secrets by decorrelating actions: use reg export to read SAM/SECURITY/SYSTEM, recover the boot key from hidden registry class values (via a minimal C program or by printing from regedit), re-import and re-save the hives in a safe VM to obtain proper hive files, and perform offline decryption with Impacket’s secretsdump. It explains the blue-team IOCs that typical tools trigger, why EDRs block reg save but not reg export, and demonstrates how small, single-purpose steps reduce detection likelihood.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
