Dump LSA

Dump LSA secrets using methods from secretsdump.py

Danger

Requires Domain Admin or Local Admin Priviledges on target Domain Controller

nxc smb <CIDR> -u <USERNAME> -p <PASSWORD> --lsa

If this command fail you can also try the old method (similar to secretdump)

nxc smb <CIDR> -u <USERNAME> -p <PASSWORD> --lsa secdump

If you found an account starting with SC_GMSA you can get the account behind: