🆕Dump Event Log Creds(4688)
Last updated
Was this helpful?
You need at least local admin privilege on the remote target
This module parses Windows logs for Event ID 4688, as well as sysmon logs for Event ID 1 to extract credentials from CMD and PowerShell commands. E.g. "net user username password /add":
nxc smb <ip> -u username -p password -M eventlog_credsLast updated
Was this helpful?
Was this helpful?

