The short answer
- When a domain controller is unreachable, Windows lets a user log in with a cached copy of their domain credential, stored as an MSCache (original) or MSCache2/DCC2 (current) hash.
- LSA secrets live in the registry under
HKEY_LOCAL_MACHINE\Security\Policy\Secretsand can hold service account passwords and other sensitive values. - MSCache2/DCC2 (hashcat mode 2100) is deliberately iterated and far slower to attack than the original MSCache (mode 1100).
- Reading these values requires SYSTEM-level access to the registry or memory — authorized administrative or forensic access only.
Intro
/!\ This is for educational purposes only, and should not be used for unauthorized access, tampering or accessed illegally without owner permission.
This page will help you to extract and manipulate the Windows Cached Credentials.
"Cached and Stored Credentials Technical Overview" from Microsoft is a must-reading to understand oh it works.
LSA secrets
LSA secrets is an area in the registry where Windows stores important information. This includes:
- Account passwords for services that are set to run by operating system users as opposed to Local System, Network Service and Local Service.
- Password used to logon to Windows if auto-logon is enabled or, generally, the password of the user logged to the console (DefaultPassword entry).
LSA secrets are stored in registry hive HKEY_LOCAL_MACHINE/Security/Policy/Secrets. Each secret has its own key. The parent key, HKEY_LOCAL_MACHINE/Security/Policy, contains the data necessary for accessing and decoding the secrets.
Tools to extract Windows Credentials & LSA secrets
These tools will extract cached credentials and LSA secrets from the Registry and/or from lsass.exe process. Thus, they can be considered as 'hacking tools' and blocked by some Antivirus. Use at your own risks !
Creddump
creddump is a python tool to extract various credentials and secrets from Windows registry hives. It currently extracts:
- LM and NT hashes (SYSKEY protected)
- Cached domain passwords
- LSA secrets
It essentially performs all the functions that bkhive/samdump2, cachedump, and lsadump2 do, but in a platform-independent way. It is also the first tool that does all of these things in an offline way (actually, Cain & Abel does, but is not open source and is only available on Windows).
CacheDump
CacheDump will create a CacheDump NT Service to get SYSTEM right and make his stuff on the registry. Then, it will retrieve the LSA Cipher Key to decrypt (rc4/hmac_md5 GloubiBoulga) cache entries values.
QuarksPwdump
quarkspwdump is a native Win32 tool to extract credentials from Windows operating systems. It currently extracts :
- Local accounts NT/LM hashes + history
- Domain accounts NT/LM hashes + history
- Cached domain password
- Bitlocker recovery information (recovery passwords & key packages)
Supported OS : XP/2003/Vista/7/2008/8
gsecdump
gsecdump extracts hashes from SAM/AD and active logon sessions.
It can also extract LSA secrets. Works for both x86 and x64. Windows 2000 - 2008.
mimikatz
mimikatz can, among other things, extract hashes and other credentials stored in memory and in registry.
Hash in hand?Submit the extracted MSCache or MSCache2 hash and OHC detects the format and runs the attack on its GPUs.
Cached domain credentials: frequently asked questions
What are Windows cached domain credentials?
A cached copy of a domain user's logon credential, stored locally so the user can still log in when the domain controller is unreachable. It is stored as a hash, not the plaintext password.
What is the difference between MSCache and MSCache2 (DCC2)?
MSCache is the original, weaker format; MSCache2 (also called DCC2) is used on current Windows and applies many more hashing iterations, making it far slower to attack.
Which hashcat mode matches a cached domain credential?
Mode 1100 for the original MSCache format, mode 2100 for MSCache2/DCC2.
What are LSA secrets?
Registry values under HKEY_LOCAL_MACHINE\Security\Policy\Secrets that store sensitive data such as service account passwords and the system's own auto-logon password, when configured.
Can OnlineHashCrack recover a cached domain credential?
Yes, submit the extracted MSCache or MSCache2 hash and OHC runs the appropriate attack on GPU.
Further reading
Related guides on Online Hash Crack: