Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ERR: Couldn't find subkey PolSecretEncryptionKey of Policy #5

Open
GoogleCodeExporter opened this issue Apr 6, 2015 · 4 comments
Open

Comments

@GoogleCodeExporter
Copy link

C:\>python cachedump.py SYSTEM SECURITY
ERR: Couldn't find subkey PolSecretEncryptionKey of Policy


How do I obtain the subkey PolSecretEncryptionKey of Policy?


Thanks,
Enda


Original issue reported on code.google.com by [email protected] on 17 May 2013 at 12:35

@seanfuture
Copy link

Appears this particular issue still exists

@moyix
Copy link
Owner

moyix commented Nov 19, 2015

What version of Windows did the hive files come from?

It appears that in Vista and later, the key name has changed. Volatility has an implementation of the updated algorithm that could be ported over (both creddump and Volatility shared the same implementation originally).

volatilityfoundation/volatility@8e7d5da

If you want to do this and submit a pull request I'd be happy to merge it.

@seanfuture
Copy link

Windows 8 was the source, so that's likely the issue.

@JensTimmerman
Copy link

JensTimmerman commented Sep 11, 2018

I ran into the same issue on win8, but it works with the patches linked above, which happen to be already merged in https://github.com/Neohapsis/creddump7

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants