« SQL mappingPlaying with LogMeIn and Hamachi »

Trackback address for this post

Trackback URL (right click and copy shortcut/link location)

1 comment

Comment from: moyix [Visitor] Email
moyixHi,

Actually you can get mscache hashes as well using my tools :) Try:

volatility cachedump -f [memory_image] -y [system hive offset] -s [security hive offset] > Domain_hash.txt

And for LSA secrets:

volatility lsadump -f [memory_image] -y [system hive offset] -s [security hive offset] > lsa_dump.txt

-moyix
03/10/09 @ 03:49