A penetration tester has successfully obtained a SAM database file. Which technique is most effective for extracting NTLM hashes while avoiding detection by traditional file-integrity monitoring systems that flag direct reads of the active SYSTEM hive?
Trap 1: Using a standard copy command to move the SAM file to a network…
Standard file copy commands will fail because the SAM file is locked by the Windows kernel for exclusive access. Attempting this will result in an access denied error, and if it were to succeed, the activity would be easily caught by EDR systems monitoring for file access patterns.
Trap 2: Executing an in-memory credential harvesting tool like Mimikatz…
Mimikatz requires SeDebugPrivilege or local administrator rights to interact with the LSASS process or extract secrets. Without these elevated privileges, the tool cannot access the memory structures necessary to dump hashes, making this method ineffective for a tester who has not yet achieved local escalation.
Trap 3: Restarting the system to force it into a recovery mode.
Restarting a production system to enter recovery mode causes unnecessary downtime and is extremely noisy. This technique is easily detected by monitoring systems that track system availability, making it an inappropriate and unprofessional choice for a penetration test where operational continuity is a requirement for the client.
- A
Using a standard copy command to move the SAM file to a network share.
Why it fails: Standard file copy commands will fail because the SAM file is locked by the Windows kernel for exclusive access. Attempting this will result in an access denied error, and if it were to succeed, the activity would be easily caught by EDR systems monitoring for file access patterns.
- B
Executing an in-memory credential harvesting tool like Mimikatz without administrative privileges.
Why it fails: Mimikatz requires SeDebugPrivilege or local administrator rights to interact with the LSASS process or extract secrets. Without these elevated privileges, the tool cannot access the memory structures necessary to dump hashes, making this method ineffective for a tester who has not yet achieved local escalation.
- C
Mounting a Volume Shadow Copy to extract the files offline.
Creating a Volume Shadow Copy allows the tester to access a point-in-time snapshot of the SAM and SYSTEM files. This bypasses the Windows file-locking mechanism, preventing access denied errors and minimizing the chance of triggering alerts that occur when attempting to open locked system files directly.
- D
Restarting the system to force it into a recovery mode.
Why it fails: Restarting a production system to enter recovery mode causes unnecessary downtime and is extremely noisy. This technique is easily detected by monitoring systems that track system availability, making it an inappropriate and unprofessional choice for a penetration test where operational continuity is a requirement for the client.