module

Windows Enumerate LSA Secrets

Disclosed
N/A
Created
May 30, 2018

Description

This module will attempt to enumerate the LSA Secrets keys within the registry. The registry value used is:
HKEY_LOCAL_MACHINE\Security\Policy\Secrets\. Thanks goes to Maurizio Agazzini and Mubix for decrypt
code from cachedump.

Author

Rob Bathurst [email protected]

Platform

Windows

Module Options

To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':


msf > use post/windows/gather/lsa_secrets
msf post(lsa_secrets) > show actions
...actions...
msf post(lsa_secrets) > set ACTION < action-name >
msf post(lsa_secrets) > show options
...show and set options...
msf post(lsa_secrets) > run

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.