[Quarks PwDump] Dump Windows Credentials
Quarks PwDump is new open
source tool to dump various types of Windows credentials: local account,
domain accounts, cached domain credentials and bitlocker. The tool is
currently dedicated to work live on operating systems limiting the risk
of undermining their integrity or stability. It requires administrator's
privileges and is still in beta test.
Quarks PwDump is a native Win32 open source tool to extract credentials from Windows operating systems.
It currently extracts :
Local accounts NT/LM hashes + history
Domain accounts NT/LM hashes + history stored in NTDS.dit file
Cached domain credentials
Bitlocker recovery information (recovery passwords & key packages) stored in NTDS.dit
JOHN and LC format are handled.
Supported OS are Windows XP / 2003 / Vista / 7 / 2008 / 8
[Quarks PwDump] Dump Windows Credentials
Reviewed by Zion3R
on
7:33 PM
Rating: