PowerDump project includes various PowerShell scripts for Windows credential harvesting.
Invoke-DpapiDump - dumps system credentials protected by DPAPI
Invoke-DpapiUserDump - dumps current user credentials protected by DPAPI
Invoke-HiveDump - dumps credentials from registry hives
Invoke-LsassDump - dumps credentials from LSASS process
DpapiDump is based on the following projects:
-
SharpDPAPI, by @harmj0y
HiveDump is based on the following projects:
-
Invoke-PowerDump from Empire, by @darkoperator and @Cx01N
-
AD utils from AADInternals, by @NestoriSyynimaa
LsassDump is based on the following project:
- MiniDump, by @cube0x0