logo

Dumping LSA secrets: a story about task decorrelation

ID: fbac8c6c-8dbb-5f91-8521-748ec4fac296

STIX ID: report--fbac8c6c-8dbb-5f91-8521-748ec4fac296

Feed Name: SensePost Blog

Date Published: 2024-07-03

Date Updated: 2026-04-30

...
...

The report details a practical method to bypass EDR controls and dump Windows LSA secrets by decorrelating actions: use reg export to read SAM/SECURITY/SYSTEM, recover the boot key from hidden registry class values (via a minimal C program or by printing from regedit), re-import and re-save the hives in a safe VM to obtain proper hive files, and perform offline decryption with Impacket’s secretsdump. It explains the blue-team IOCs that typical tools trigger, why EDRs block reg save but not reg export, and demonstrates how small, single-purpose steps reduce detection likelihood.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.