Extracting Credentials From Memory Dump

Extracts cached credentials, password hashes, Kerberos tickets, and authentication tokens from Windows memory dumps using Volatility 3, Mimikatz, and pypykatz. Use when performing memory forensics or incident response on an LSASS or full memory dump and you need to recover credentials or Kerberos material for investigation.

gabrielmoreira Updated 17 repo stars

File contents

gabrielmoreira/agent-skills-mirror/tree/main/mirrors/repos/mukul975@Anthropic-Cybersecurity-Skills/skills/extracting-credentials-from-memory-dump commit 0d91213d1a

Frequently asked questions

npx skillmds@latest add gabrielmoreira/extracting-credentials-from-memory-dump