How to break into registry to explore HKLM\SAM and HKLM\SECURITY keys

July 16, 2008 – 5:50 AM

The Registry Editor will not allow you to navigate through HKEY_LOCAL_MACHINE\SAM and HKEY_LOCAL_MACHINE\SECURITY hives. These hives are protected by the System Account and currently logged on user or member of Administrators Group do not have permissions to view them.

To view the the registry entries under SAM or SECURITY hive, you need to run the Registory Editor under the security context of System Account. To run Registry Editor under the security context of System Account, use the following command with Psexec.exe:

Psexec.exe –s –i regedit.exe

Psexec.exe can be downloaded at the following URL: http://technet.microsoft.com/en-us/sysinternals/bb896649.aspx.

Source: http://www.windowsnetworking.com/kbase/WindowsTips/Windows2000/RegistryTips/RegistryTools/HowtobreakintoregistrytoexploreHKLMSAMandHKLMSECURITYkeys.html

You must be logged in to post a comment.