GITEST
Back to Playbooks
Post-Exploitation

post-credential-dumping

Windows credential dumping post-exploitation. LSASS dump via procdump/nanodump/comsvcs, SAM/SYSTEM/SECURITY hive extraction, NTDS.dit dump via shadow copy, DCSync attack, LSA secrets, cached credentials, DPAPI, hash cracking, pass-the-hash.

Slug

post-credential-dumping

Category

Post-Exploitation

Run Playbook

/gitest post-credential-dumping