Mastering Windows Network Forensics and Investigation, 2nd Edition
by Steven Anson, Steve Bunting, Ryan Johnson, Scott Pearson
Extracting LSA Secrets
We can only imagine the chatter on the hacker network on the day that NT was released and the hackers discovered a registry key named SECURITY\Policy\Secrets. Its name alone makes it an attractive target. We could hope that perhaps Microsoft placed it there by that name, filling it with irrelevant data just to create a diversion for the hackers of the world. Such was hardly the case, because its contents were just what the name suggested. What’s more, this same key and content exist today in the most current versions of Windows.
LSA stands for Local Security Authority. The security hive key is part of the registry, although you can’t access this key through regedit. The previously mentioned key (SECURITY\Policy\Secrets ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access