Credentials in Registry
https://attack.mitre.org/techniques/T1552/002/
Techniques
CMD
# String matching in registry
reg query HKLM /f password /t REG_SZ /s
reg query HKCU /f password /t REG_SZ /s
# Putty
reg query "HKCU\Software\SimonTatham\PuTTY\Sessions" /t REG_SZ /s
# VNC
reg query "HKCU\Software\ORL\WinVNC3\Password"
# Windows autologin
reg query "HKLM\SOFTWARE\Microsoft\Windows NT\Currentversion\Winlogon"Metasploit
PowerSploit
Last updated