Credential Dumping

Extracts credentials from Active Directory: DCSync replication, NTDS.dit database extraction, SAM hive dump, Azure AD Connect (ADSync) credential extraction, LAPS passwords (legacy + Windows LAPS), gMSA passwords (KDS root key + GoldenGMSA), dMSA exploitation (BadSuccessor CVE-2025-21293), DSRM credentials, and EFS-encrypted file decryption.

blacklanternsecurity 952be93 26.7 KB Updated

File contents

blacklanternsecurity/red-run/tree/main/skills/ad/credential-dumping commit 952be93a52

Frequently asked questions

npx skillmds@latest add blacklanternsecurity/credential-dumping