Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Windows7 lsass.DMP under Pypykatz 069 #149

Open
sudo-joe opened this issue Feb 29, 2024 · 1 comment
Open

Windows7 lsass.DMP under Pypykatz 069 #149

sudo-joe opened this issue Feb 29, 2024 · 1 comment

Comments

@sudo-joe
Copy link

Hello
dumped lsass with taskmgr as admin on a Windows7.

[The file is located at:]
[c:\Users\test\App Data\Local\Temp\lsass.DMP]

pypykatz lsa minidumd lsass.DMP

Surprisingly the output shows only the hash of one Windows7 user (the one i am mostly using) and it's password in cleartext
The other Windows7 users are not listed.

If I am using ' pypykatz registry....´ all Windows users are listed...

Question:
Any idea why Pypykatz 069 does only list one user?

Thanks a lot in advance for any feedback!

PS:
No idea why the lsass.DMP is writtern to user test [c:\Users\test\App Data\Local\Temp\lsass.DMP] and not to user Admin..... since I logged into Windows as Admin

@skelsec
Copy link
Owner

skelsec commented Apr 5, 2024

I believe you're expecting the same information to be acquired from the registry and form the lsass but those are two different things which while do have some relation with one another ultimately don't store the same information.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants