Skip to content

Credential Access

Harvesting passwords, keys and tickets from memory, disk and secret stores — LSASS, browsers, SSH keys and Active Directory.

Credential Accessbeginner
Reading saved passwords and session cookies from a browser's local profile store by calling the same OS decryption API a legitimate password manager would use.
windowslinuxmacos
Credential Accessintermediate
Requesting Kerberos service tickets for accounts with a Service Principal Name, then attempting offline cracking of the ticket's encrypted portion to recover the service account's password.
windows
Credential Accessintermediate
Creating a memory dump of the LSASS process to extract NTLM hashes, Kerberos tickets and (on older systems) cleartext credentials for offline parsing.
windows
Credential Accessadvanced
Recovering the Active Directory database file, which holds every domain account's password hash, typically via a Volume Shadow Copy of the domain controller's system volume.
windows
Credential Accessbeginner
Saving the SAM, SYSTEM and SECURITY registry hives to disk to extract local account password hashes offline using the boot key stored in SYSTEM.
windows
Credential Accessbeginner
Harvesting unencrypted private keys and agent-forwarding sockets from a compromised host to enable onward SSH access to every system that trusts them.
windowslinuxmacos