Pentesting Notebook
Ctrlk
  • Offensive security
    • Tooling
    • Virtualisation
    • Active Directory
      • Domain Recon
      • Object Permissions
      • Privileged Groups
      • Group Policy
      • Kerberos
      • AD CS
      • MS SQL Servers
      • SCCM
      • Credential Theft
        • Mimikatz
        • LSASS: NTLM
        • LSASS: Secrets
        • SAM
        • Kerberos encryption keys
        • Domain Cached Credentials (DCC)
        • Kerberos Tickets
        • DCSync
        • Clear Text from RDP
        • Remote Cred Dumping
        • Extract from .DMP file
      • LAPS
      • Forest & Domain Trusts
      • Domain Dominance
      • User Impersonation
      • Lateral Movement
      • Relaying
      • Pivoting
      • Zerologon
      • BloodyAD
      • Expired Passwords
    • Infrastructure
    • OSEP: Checklist
    • AV Evasion
    • UAC Bypass
    • Applocker
    • Initial compromise
    • Privilege Escalation
    • Persistence
    • Data Protection API
    • Windows Script Host
    • Cobalt Strike
    • MetaSploit
    • Linux
    • macOS
    • SQLMap
    • Regex / sed
    • Cracking
    • Misc.
    • Visual Studio notes
  • Generic
    • Commands
    • Web
    • Fixing Errors
Powered by GitBook
On this page
  1. Offensive security
  2. Active Directory

Credential Theft

MimikatzLSASS: NTLMLSASS: SecretsSAMKerberos encryption keysDomain Cached Credentials (DCC)Kerberos TicketsDCSyncClear Text from RDPRemote Cred DumpingExtract from .DMP file

Last updated 1 year ago