daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

pcap-credential-extraction.md (11387B)


      1 ---
      2 title: "pcap-credential-extraction"
      3 description: "ldap.simple or http.authorization or ftp.request.command == PASS or ntlmssp or kerberos"
      4 category: tools
      5 tags: ["tools", "kerberos", "ntlm", "sql-injection"]
      6 tools: ["Hashcat", "John", "tshark"]
      7 difficulty: intermediate
      8 updated: "2026-08-10"
      9 source: "vault:Tools/pcap-credential-extraction-cheatsheet.md"
     10 ---
     11 # PCAP Credential Extraction Cheat Sheet
     12 
     13 ## Quick Reference Table
     14 
     15 | Protocol | Port | Tool | Filter/Command |
     16 |----------|------|------|----------------|
     17 | LDAP Simple Bind | 389 | tshark | `tshark -r file.pcap -Y "ldap.simple" -T fields -e ldap.name -e ldap.simple` |
     18 | HTTP Basic Auth | 80/8080 | tshark | `tshark -r file.pcap -Y "http.authorization" -T fields -e http.authorization` |
     19 | FTP | 21 | tshark | `tshark -r file.pcap -Y "ftp.request.command == USER or ftp.request.command == PASS" -T fields -e ftp.request.arg` |
     20 | Telnet | 23 | tshark | `tshark -r file.pcap -Y "telnet" -T fields -e telnet.data` |
     21 | SMTP Auth | 25/587 | tshark | `tshark -r file.pcap -Y "smtp.auth.password" -T fields -e smtp.auth.username -e smtp.auth.password` |
     22 | POP3 | 110 | tshark | `tshark -r file.pcap -Y "pop.request.command == USER or pop.request.command == PASS" -T fields -e pop.request.parameter` |
     23 | IMAP | 143 | tshark | `tshark -r file.pcap -Y "imap.request contains LOGIN" -T fields -e imap.request` |
     24 | SNMP | 161 | tshark | `tshark -r file.pcap -Y "snmp" -T fields -e snmp.community` |
     25 | MySQL | 3306 | tshark | `tshark -r file.pcap -Y "mysql.passwd" -T fields -e mysql.user -e mysql.passwd` |
     26 | NTLMSSP | Various | tshark | `tshark -r file.pcap -Y "ntlmssp.auth.username" -T fields -e ntlmssp.auth.domain -e ntlmssp.auth.username` |
     27 | Kerberos | 88 | tshark | `tshark -r file.pcap -Y "kerberos.CNameString" -T fields -e kerberos.CNameString -e kerberos.realm` |
     28 | HTTP POST | 80/443 | tshark | `tshark -r file.pcap -Y "http.request.method == POST" -T fields -e http.file_data` |
     29 
     30 ---
     31 
     32 ## Wireshark Display Filters
     33 
     34 ### Authentication Protocols
     35 ```bash
     36 # All authentication-related traffic
     37 ldap.simple or http.authorization or ftp.request.command == PASS or ntlmssp or kerberos
     38 
     39 # LDAP bind requests with credentials
     40 ldap.bindRequest and ldap.simple
     41 
     42 # LDAP simple bind only
     43 ldap.protocolOp == 0
     44 
     45 # HTTP Basic/Digest Authentication
     46 http.authorization
     47 
     48 # HTTP POST requests (login forms)
     49 http.request.method == POST
     50 
     51 # NTLM Authentication
     52 ntlmssp.auth.username
     53 
     54 # Kerberos traffic
     55 kerberos.CNameString
     56 
     57 # FTP credentials
     58 ftp.request.command == USER or ftp.request.command == PASS
     59 
     60 # SMB/CIFS authentication
     61 smb.uid or smb2.session_id
     62 ```
     63 
     64 ### By Service Port
     65 ```bash
     66 # LDAP
     67 tcp.port == 389 or tcp.port == 636
     68 
     69 # HTTP/HTTPS
     70 tcp.port == 80 or tcp.port == 443 or tcp.port == 8080
     71 
     72 # FTP
     73 tcp.port == 21
     74 
     75 # SSH (encrypted, but can identify users)
     76 tcp.port == 22
     77 
     78 # Telnet
     79 tcp.port == 23
     80 
     81 # SMTP
     82 tcp.port == 25 or tcp.port == 587
     83 
     84 # DNS (for recon)
     85 udp.port == 53
     86 
     87 # Kerberos
     88 tcp.port == 88 or udp.port == 88
     89 
     90 # SMB
     91 tcp.port == 445 or tcp.port == 139
     92 ```
     93 
     94 ---
     95 
     96 ## tshark Commands
     97 
     98 ### LDAP Credentials
     99 ```bash
    100 # Extract LDAP simple bind credentials
    101 tshark -r capture.pcap -Y "ldap.simple" -T fields -e ldap.name -e ldap.simple
    102 
    103 # LDAP with more context
    104 tshark -r capture.pcap -Y "ldap.bindRequest" -T fields -e ip.src -e ip.dst -e ldap.name -e ldap.simple
    105 
    106 # All LDAP operations
    107 tshark -r capture.pcap -Y "ldap" -T fields -e frame.number -e ldap.protocolOp -e ldap.name -e ldap.simple
    108 
    109 # To see whole packet and info
    110 sudo tshark -r UserInfo.exe.pcap -Y "ldap.simple" -V
    111 ```
    112 
    113 ### HTTP Credentials
    114 ```bash
    115 # HTTP Basic Auth (base64 encoded)
    116 tshark -r capture.pcap -Y "http.authorization" -T fields -e ip.src -e http.host -e http.authorization
    117 
    118 # Decode Base64 inline
    119 tshark -r capture.pcap -Y "http.authorization" -T fields -e http.authorization | cut -d' ' -f2 | base64 -d
    120 
    121 # HTTP POST data (form submissions)
    122 tshark -r capture.pcap -Y "http.request.method == POST" -T fields -e http.host -e http.request.uri -e http.file_data
    123 
    124 # Look for password fields in POST
    125 tshark -r capture.pcap -Y "http.request.method == POST" -T fields -e http.file_data | grep -iE "(pass|pwd|password|passwd)"
    126 
    127 # HTTP cookies (session tokens)
    128 tshark -r capture.pcap -Y "http.cookie" -T fields -e http.host -e http.cookie
    129 ```
    130 
    131 ### FTP Credentials
    132 ```bash
    133 # FTP username and password
    134 tshark -r capture.pcap -Y "ftp.request.command == USER or ftp.request.command == PASS" -T fields -e ip.src -e ftp.request.command -e ftp.request.arg
    135 
    136 # All FTP commands
    137 tshark -r capture.pcap -Y "ftp.request" -T fields -e frame.time -e ip.src -e ftp.request.command -e ftp.request.arg
    138 ```
    139 
    140 ### SMTP/Email Credentials
    141 ```bash
    142 # SMTP AUTH credentials
    143 tshark -r capture.pcap -Y "smtp.auth.password" -T fields -e smtp.auth.username -e smtp.auth.password
    144 
    145 # SMTP commands
    146 tshark -r capture.pcap -Y "smtp.req.command" -T fields -e smtp.req.command -e smtp.req.parameter
    147 ```
    148 
    149 ### SMB/Windows Authentication
    150 ```bash
    151 # NTLMSSP usernames
    152 tshark -r capture.pcap -Y "ntlmssp.auth.username" -T fields -e ip.src -e ntlmssp.auth.domain -e ntlmssp.auth.username
    153 
    154 # SMB2 session setup
    155 tshark -r capture.pcap -Y "smb2.cmd == 1" -T fields -e ip.src -e ip.dst -e smb2.acct -e smb2.domain
    156 
    157 # Extract NTLMv2 hashes (for cracking)
    158 tshark -r capture.pcap -Y "ntlmssp.auth.ntresponse" -T fields -e ntlmssp.auth.username -e ntlmssp.auth.domain -e ntlmssp.auth.ntresponse
    159 ```
    160 
    161 ### Kerberos
    162 ```bash
    163 # Kerberos principals
    164 tshark -r capture.pcap -Y "kerberos.CNameString" -T fields -e ip.src -e kerberos.CNameString -e kerberos.realm
    165 
    166 # AS-REQ (initial auth)
    167 tshark -r capture.pcap -Y "kerberos.msg_type == 10" -T fields -e kerberos.CNameString -e kerberos.realm
    168 ```
    169 
    170 ### SNMP Community Strings
    171 ```bash
    172 # SNMP community strings (like passwords)
    173 tshark -r capture.pcap -Y "snmp.community" -T fields -e ip.src -e ip.dst -e snmp.community
    174 ```
    175 
    176 ### Database Credentials
    177 ```bash
    178 # MySQL login attempts
    179 tshark -r capture.pcap -Y "mysql.user" -T fields -e ip.src -e mysql.user
    180 
    181 # PostgreSQL
    182 tshark -r capture.pcap -Y "pgsql.type == 'p'" -T fields -e pgsql.user -e pgsql.password
    183 ```
    184 
    185 ---
    186 
    187 ## Automated Tools
    188 
    189 ### PCredz
    190 ```bash
    191 # Install
    192 git clone https://github.com/lgandx/PCredz.git
    193 
    194 # Run on pcap
    195 python3 Pcredz -f capture.pcap
    196 
    197 # Run on interface (live capture)
    198 python3 Pcredz -i eth0
    199 ```
    200 
    201 ### NetworkMiner (GUI)
    202 ```bash
    203 # Install on Linux
    204 sudo apt install networkminer
    205 
    206 # Or download from: https://www.netresec.com/?page=NetworkMiner
    207 # Open pcap file -> Credentials tab shows extracted creds
    208 ```
    209 
    210 ### Chaosreader
    211 ```bash
    212 # Extract all sessions and files
    213 chaosreader capture.pcap
    214 
    215 # Creates HTML report with extracted data
    216 ```
    217 
    218 ### ngrep
    219 ```bash
    220 # Search for password patterns
    221 ngrep -I capture.pcap -q "pass|pwd|password|passwd"
    222 
    223 # Search for specific strings
    224 ngrep -I capture.pcap -q "admin"
    225 
    226 # Search in specific protocol
    227 ngrep -I capture.pcap -q "PASS" port 21
    228 ```
    229 
    230 ### dsniff
    231 ```bash
    232 # Extract passwords from pcap
    233 dsniff -p capture.pcap
    234 ```
    235 
    236 ---
    237 
    238 ## Quick & Dirty Methods
    239 
    240 ### strings + grep
    241 ```bash
    242 # Find all readable strings
    243 strings capture.pcap | less
    244 
    245 # Look for password patterns
    246 strings capture.pcap | grep -iE "(password|passwd|pass|pwd).*[:=]"
    247 
    248 # Look for usernames
    249 strings capture.pcap | grep -iE "(user|username|login|uname).*[:=]"
    250 
    251 # Find base64 strings (potential encoded creds)
    252 strings capture.pcap | grep -E "^[A-Za-z0-9+/]{20,}={0,2}$"
    253 
    254 # Find email addresses
    255 strings capture.pcap | grep -oE "[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}"
    256 
    257 # Find IP addresses
    258 strings capture.pcap | grep -oE "\b([0-9]{1,3}\.){3}[0-9]{1,3}\b"
    259 
    260 # Find URLs
    261 strings capture.pcap | grep -oE "https?://[^ ]+"
    262 ```
    263 
    264 ### xxd / hexdump
    265 ```bash
    266 # View hex dump with ASCII
    267 xxd capture.pcap | less
    268 
    269 # Search for string in hex
    270 xxd capture.pcap | grep -i "password"
    271 
    272 # Hexdump with strings highlighted
    273 hexdump -C capture.pcap | less
    274 ```
    275 
    276 ---
    277 
    278 ## Wireshark GUI Tips
    279 
    280 ### Follow Streams
    281 1. Right-click packet → Follow → TCP/UDP/HTTP Stream
    282 2. Shows full conversation in readable format
    283 3. Great for seeing complete authentication exchanges
    284 
    285 ### Export Objects
    286 1. File → Export Objects → HTTP/SMB/TFTP/etc.
    287 2. Extracts files transferred over network
    288 3. May contain config files with credentials
    289 
    290 ### Useful Columns to Add
    291 - `ldap.name` - LDAP bind DN
    292 - `ldap.simple` - LDAP simple bind password
    293 - `http.authorization` - HTTP auth headers
    294 - `ftp.request.arg` - FTP command arguments
    295 
    296 ### Protocol Hierarchy
    297 1. Statistics → Protocol Hierarchy
    298 2. Quick overview of what protocols are in capture
    299 3. Helps identify what to look for
    300 
    301 ---
    302 
    303 ## Hash Extraction for Cracking
    304 
    305 ### NTLMv2 Hashes
    306 ```bash
    307 # Extract for hashcat/john
    308 tshark -r capture.pcap -Y "ntlmssp.auth" -T fields \
    309   -e ntlmssp.auth.username \
    310   -e ntlmssp.auth.domain \
    311   -e ntlmssp.ntlmserverchallenge \
    312   -e ntlmssp.auth.ntresponse \
    313   -e ntlmssp.auth.lmresponse
    314 
    315 # Format for hashcat (mode 5600):
    316 # username::domain:ServerChallenge:NTProofStr:NTLMv2Response
    317 ```
    318 
    319 ### Kerberos Tickets (AS-REP Roasting)
    320 ```bash
    321 # Extract AS-REP for users without pre-auth
    322 tshark -r capture.pcap -Y "kerberos.msg_type == 11" -T fields -e kerberos.cipher
    323 ```
    324 
    325 ### HTTP Digest Auth
    326 ```bash
    327 # Extract digest for cracking
    328 tshark -r capture.pcap -Y "http.authbasic" -T fields -e http.authorization
    329 ```
    330 
    331 ---
    332 
    333 ## One-Liners
    334 
    335 ```bash
    336 # Quick credential dump - tries multiple protocols
    337 tshark -r capture.pcap -Y "ldap.simple or http.authorization or ftp.request.command == PASS or smtp.auth.password" -T fields -e frame.number -e ip.src -e ip.dst -e _ws.col.Protocol -e _ws.col.Info 2>/dev/null
    338 
    339 # Find all cleartext passwords (broad search)
    340 strings capture.pcap | grep -iE "^.{0,30}(password|passwd|pass|pwd)[^a-z].{0,50}$" | sort -u
    341 
    342 # Extract and decode all HTTP Basic Auth
    343 tshark -r capture.pcap -Y "http.authorization contains Basic" -T fields -e http.authorization | while read line; do echo "$line" | cut -d' ' -f2 | base64 -d; echo; done
    344 
    345 # List all unique source IPs with auth attempts
    346 tshark -r capture.pcap -Y "ldap.simple or http.authorization or ftp.request.command == PASS" -T fields -e ip.src | sort -u
    347 
    348 # Count auth attempts by protocol
    349 tshark -r capture.pcap -Y "ldap.simple or http.authorization or ftp.request.command == PASS" -T fields -e _ws.col.Protocol | sort | uniq -c
    350 ```
    351 
    352 ---
    353 
    354 ## Common Credential Locations by Protocol
    355 
    356 | Protocol | Where to Look |
    357 |----------|---------------|
    358 | LDAP | `ldap.simple` field in bindRequest |
    359 | HTTP Basic | `Authorization: Basic <base64>` header |
    360 | HTTP Form | POST body, look for password/passwd/pass fields |
    361 | FTP | USER and PASS commands in cleartext |
    362 | Telnet | Full session in cleartext |
    363 | SMTP | AUTH LOGIN/PLAIN commands (base64) |
    364 | POP3 | USER and PASS commands |
    365 | IMAP | LOGIN command arguments |
    366 | SNMP | Community string (like a password) |
    367 | VNC | Challenge-response (hashcat mode 7900) |
    368 | RDP | NLA uses CredSSP/NTLMv2 |
    369 | MySQL | mysql.passwd field |
    370 | PostgreSQL | Startup message or password message |
    371 
    372 ---
    373 
    374 ## Tips
    375 
    376 1. **Always check for TLS/SSL** - If traffic is encrypted, you need the private key or to perform MITM
    377 2. **Time-based correlation** - Failed logins often followed by successful ones reveal valid creds
    378 3. **Check both directions** - Server responses may echo back usernames
    379 4. **Look at DNS** - Reveals internal hostnames and structure
    380 5. **Export HTTP objects** - Config files often contain hardcoded creds
    381 6. **Check for password reuse** - Same creds may work elsewhere