Administrator account
Extract credentials from LSASS
Extract Credentials from SAM
Extract Credentials from LSA
Extract dpapi
Search Password Files
Search Stored Password
Chrome
Token Manipulation
Account Operators Group Membership
Add User
Import PowerView
Add DCSync Rights
DCSync
Azure Admin Group Membership
If an user is Admin of Azure Group we can try to exploit Azure AD Sync to grab the administrator password:
Then run this command being inside the path C:\Program Files\Microsoft Azure AD Sync\Bin :
Last updated