Impacket `reg` Walkthrough Demonstrates Remote Registry Access, Credential Harvesting and Persistence

· Original article ↗

Summary

A lab walkthrough shows how Impacket `reg` can use authenticated SMB access to enumerate and modify a Windows registry, export credential hives, enable RDP and establish Run-key persistence, alongside defensive monitoring and hardening guidance.

Key points

  • The walkthrough demonstrates password, NTLM hash, AES Kerberos key and ticket-cache authentication to a Windows Server 2019 domain controller over SMB.
  • Remote registry queries reveal system configuration, services and installed software for post-exploitation reconnaissance.
  • SAM, SYSTEM and SECURITY hives can be exported to an SMB share and parsed offline to recover local account hashes without accessing LSASS memory.
  • Registry writes can enable RDP and create or remove keys and values, supporting lateral movement and configuration changes.
  • The lab chain transfers a reverse-shell payload and registers it under the Windows Run key for execution at logon.
  • Suggested defenses include restricting RemoteRegistry and SMB access, protecting privileged credentials and registry hives, and monitoring Run-key changes, remote-registry activity and outbound connections.

Article Details

Topic
Remote Windows registry post-exploitation with impacket-reg in an isolated Active Directory lab

Indicators of compromise

TypeIndicatorContext
IPV4192[.]168[.]1[.]6Operator-controlled Kali host used as the registry-hive export destination and reverse-shell callback listener in the isolated lab demonstration.

MITRE ATT&CK

Vendors

Products

Tools

Related Articles