Creds Hunting Windows

  • find creds across the file system

  • EG: we have access to an IT admins workstation

    • What might an IT admin be doing on a day-to-day basis & which of those tasks may require credentials?
  • Key terms to search for
  • Use LaZagne to discover creds on web browsers
    • start lazagne.exe all - LaZagne Command
  • Using findstr
    • findstr /SIM /C:"password" *.txt *.ini *.cfg *.config *.xml *.git *.ps1 *.yml
  • SYSVOL Share - https://networkencyclopedia.com/sysvol-share/