Pentesting Notebook
search
⌘Ctrlk
Pentesting Notebook
  • Offensive security
    • Tooling
    • Virtualisation
    • Active Directory
      • Domain Recon
      • Object Permissions
      • Privileged Groups
      • Group Policy
      • Kerberos
      • AD CS
      • MS SQL Servers
      • SCCM
      • Credential Theft
        • Mimikatz
        • LSASS: NTLM
        • LSASS: Secrets
        • SAM
        • Kerberos encryption keys
        • Domain Cached Credentials (DCC)
        • Kerberos Tickets
        • DCSync
        • Clear Text from RDP
        • Remote Cred Dumping
        • Extract from .DMP file
      • LAPS
      • Forest & Domain Trusts
      • Domain Dominance
      • User Impersonation
      • Lateral Movement
      • Relaying
      • Pivoting
      • Zerologon
      • BloodyAD
      • Expired Passwords
      • Create machine account easily
    • Infrastructure
    • OSEP: Checklist
    • AV Evasion
    • UAC Bypass
    • Applocker
    • Initial compromise
    • Privilege Escalation
    • Persistence
    • Data Protection API
    • Windows Script Host
    • Cobalt Strike
    • MetaSploit
    • Linux
    • macOS
    • SQLMap
    • Regex / sed
    • Cracking
    • Misc.
    • Visual Studio notes
  • Generic
    • Commands
    • Web
    • Fixing Errors
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. Offensive securitychevron-right
  2. Active Directory

Credential Theft

Mimikatzchevron-rightLSASS: NTLMchevron-rightLSASS: Secretschevron-rightSAMchevron-rightKerberos encryption keyschevron-rightDomain Cached Credentials (DCC)chevron-rightKerberos Ticketschevron-rightDCSyncchevron-rightClear Text from RDPchevron-rightRemote Cred Dumpingchevron-rightExtract from .DMP filechevron-right

Last updated 1 year ago