Please enable JavaScript.
Coggle requires JavaScript to display documents.
Windows Credentials (Registry (SAM (Extract hash (secretsdump.py
fgdump…
Windows Credentials
Registry
-
SAM
Extract hash
- secretsdump.py
- fgdump
- pwdump7
- Cain & abel
- samdump2 + bhive
-
Crack pwd
- JtR
- Cain & Abel
- Ophcrack
- Hashcat
-
-
Processes
LSASS
Pass-the-hash
- wce
- psexec
- Metasploit
- pth-net
-
-
Services
- Powershell / services.msc
- LSAchamp2
- LSASecretsDump
- pwdumpx
- gsecdump
- Cain & Abel
-
-
Events
- gpedit.msc (audit log)
- powershell
Accounts
- net users
- net accounts
- Powershell
File System
- Sam file in .vhd
- Unaffected.txt
- backups
- C:\Users
- \<domain-controller>\sysvol\xml (gppdecrypt.rb)