🆕Dump Event Log Creds(4688)
Parses Windows Event ID 4688 and Sysmon Logs
nxc smb <ip> -u username -p password -M eventlog_credsLast updated
Was this helpful?
nxc smb <ip> -u username -p password -M eventlog_credsLast updated
Was this helpful?
Was this helpful?