Skip to content

Blog

Stuff I find out. Short notes, quick wins, things worth keeping.

LSA Secrets: Reading SC Service Passwords with the Registry Copy Trick

You are SYSTEM on a domain-joined Windows box. You want the service account passwords stored in the LSA secret vault. The direct API path (LsaOpenSecret / LsaQuerySecret) works for DPAPI_SYSTEM and $MACHINE.ACC, but _SC_ prefixed secrets, the ones holding service account passwords, return ACCESS_DENIED even under SYSTEM. So you copy the encrypted registry blobs to a temp key and read them through LsaRetrievePrivateData instead.