Credential Access & Dumping
Dumping Credentials from Lsass Process Memory with MimikatzDumping Lsass Without MimikatzDumping Lsass without Mimikatz with MiniDumpWriteDumpDumping Hashes from SAM via RegistryDumping SAM via esentutl.exeDumping LSA SecretsDumping and Cracking mscash - Cached Domain CredentialsDumping Domain Controller Hashes Locally and RemotelyDumping Domain Controller Hashes via wmic and Vssadmin Shadow CopyNetwork vs Interactive LogonsReading DPAPI Encrypted Secrets with Mimikatz and C++Credentials in RegistryPassword FilterForcing WDigest to Store Credentials in PlaintextDumping Delegated Default Kerberos and NTLM Credentials w/o Touching LsassIntercepting Logon Credentials via Custom Security Support Provider and Authentication PackagesPulling Web Application Passwords by Hooking HTML Input FieldsIntercepting Logon Credentials by Hooking msv1_0!SpAcceptCredentialsCredentials Collection via CredUIPromptForCredentials
Last updated