Back to Playbooks
Post-Exploitation
post-credential-dumping
Windows credential dumping post-exploitation. LSASS dump via procdump/nanodump/comsvcs, SAM/SYSTEM/SECURITY hive extraction, NTDS.dit dump via shadow copy, DCSync attack, LSA secrets, cached credentials, DPAPI, hash cracking, pass-the-hash.
Slug
post-credential-dumping
Category
Post-Exploitation
Run Playbook
/gitest post-credential-dumping