SilentNimvest — a tool for extracting Windows secrets while evading EDR

⚙️ Tools2026-04-13, 07:45
The tool is a Nim‑based utility that dumps local user hashes, cached domain authentication data, and LSA secrets from the SAM and SECURITY registry hives. It implements the SilentHarvest technique, which leverages SeBackupPrivilege rather than requiring NT AUTHORITY\SYSTEM access. By operating through the RegQueryMultipleValuesW API, the tool reduces the likelihood of EDR detection.
💬 Discuss
Vendors
Github
Products
Edr
Nim
Regquerymultiplevaluesw
Sam
Security
Silentnimvest
More
Published
2026-04-13, 07:45