Skip to main content

SAM / SYSTEM Dump

SAM database contains local account NTLM hashes. Needs SYSTEM + SAM hives.

Copy Registry Hives

Volume Shadow Copy (If Locked)

Extract Hashes (Attacker)

Crack NTLM Hashes


DPAPI — Saved Passwords

DPAPI protects Chrome/Edge passwords, Wi-Fi keys, RDP credentials.

Chrome/Edge Passwords

Encrypted DB location:

Decrypt with Mimikatz

Decrypt with SharpChrome

Wi-Fi Passwords via DPAPI


Windows Vault / Credential Manager

List Stored Credentials

Exploit Saved Credentials (runas /savecred)

If cmdkey /list shows stored credentials:

Extract with Mimikatz


Unattend.xml / Sysprep Files

Deployment files often contain plaintext or base64-encoded passwords.

Common Locations

Full list of paths:

Password Format in Unattend.xml

Decode Base64 Password


PowerShell History

History File Location

Default:

Read History for All Users

Search for Credentials

CMD History