Forum Discussion

zlate81's avatar
zlate81
Copper Contributor
Jul 09, 2025

MDE not detecting regsecrets.py from impacket-toolkit

In a recent red-team engagement we got exposed to the regsecrets.py toolkit which made it possible to extract SAM hive without any detection from the MDE. I have tried to use advanced hunting to see...

Resources