
VMkatz
Extract Windows credentials directly from VM memory snapshots and virtual disks
digital-forensicsexploitationforensics+7

Extract Windows credentials directly from VM memory snapshots and virtual disks

CredsHunter - Credential Hunting scripts for Windows and Linux OS

Brute-force tool that recovers full executable paths from Windows prefetch hashes using bodyfiles, supporting XP, Vista, and 2008 hash functions for…