Hash Dumping Commands
29 Hash Dumping commands from the Credential Attacks category, each with its placeholders, supported authentication methods and upstream references.
Tools covered: Rubeus.exe, impacket-dpapi, impacket-secretsdump, lsassy, mimikatz.exe, nxc, pypykatz
- Impacket DPAPI Masterkey Decrypt DPAPI masterkey using user password to derive DPAPI encryption key
- Impacket Secrets Dump Dump hashes from remote Windows system (SAM, LSA, NTDS)
- Impacket Targeted DCSync (Single User) DCSync only one specific account instead of replicating the whole NTDS. Massively reduces noise on the wire…
- Lsassy LSASS Dump Remotely dump LSASS credentials using lsassy
- Mimikatz Credential Dump Extract plaintext passwords and hashes from all available sources
- Mimikatz dpapi::masterkey Decrypt a DPAPI master key using the owner's plaintext password (or NT hash). Required step before…
- Mimikatz lsadump::dcsync Pull a single user's NT hash and Kerberos keys directly from a DC via the MS-DRSR replication protocol. No…
- Mimikatz lsadump::sam Extract local SAM hashes (built-in Administrator, local users) from a live Windows host. Run as SYSTEM…
- Mimikatz sekurlsa::logonpasswords Dump credentials (NT hashes, Kerberos keys, plaintext where wdigest is enabled, MSV1_0) from LSASS for every…
- Mimikatz Ticket Extraction Extract cached Kerberos tickets
- NetExec dpapi_hash Module Extract DPAPI master-key hashes for offline cracking with hashcat (mode 15300 for v1 / 15900 for v2).…
- NetExec eventlog_creds Module Harvest plaintext credentials passed to processes (typically scheduled tasks, runas, custom scripts) from…
- NetExec gpp_password Module Search SYSVOL for Group Policy Preferences XML files containing AES-encrypted cpassword values, then decrypt…
- NetExec lsassy Module (Remote LSASS Dump) Dump LSASS remotely via the lsassy module — uses procdump/comsvcs/dllinjection methods, parses on the fly…
- NetExec masky Module Remotely abuse a vulnerable certificate template (typically User) to enroll certificates as every…
- NetExec nanodump Module Dump LSASS using the nanodump BOF/PE technique — minimal dump, fewer EDR signatures than full minidumps,…
- NetExec SMB Backup Operator Abuse Backup Operators group membership to dump registry hives (SAM, SYSTEM, SECURITY)
- NetExec SMB DPAPI Hash Extract DPAPI master key hashes from remote hosts for offline cracking
- NetExec SMB HandleKatz Dump LSASS credentials by duplicating process handles to bypass PPL/AV restrictions
- NetExec SMB Masky Abuse ADCS to request certificates for all logged-on users and extract their NT hashes
- NetExec SMB NTDS Dump Dump the NTDS.dit database from a Domain Controller to extract all domain hashes
- NetExec SMB NTDSUtil Dump Dump NTDS.dit using ntdsutil IFM method (creates install-from-media backup)
- NetExec SMB SAM & LSA Dump Dump SAM database and LSA secrets from a remote Windows system via NetExec
- NetExec SMB WDigest Enable Enable or disable WDigest authentication to force cleartext password caching in LSASS
- NetExec timeroast Module Timeroast: brute computer-account passwords via the MS-SNTP authenticated NTP exchange. The DC signs replies…
- Pypykatz SAM Dump Extract hashes from SAM and SYSTEM registry files
- Rubeus dump Extract every Kerberos ticket currently in memory across all logon sessions. Requires elevation for other…
- Rubeus harvest Continuously monitor LSA for new TGTs and auto-renew them before expiry. Long-running collection — pair with…
- Rubeus tgtdeleg Extract a usable TGT for the current user without elevation by abusing the GSS-API delegation flow. The…