
adiskreader-secretsdump
Extract registry and NTDS secrets from local or remote disk images
digital-forensicsincident-responsepassword-attacks+3
45

Extract registry and NTDS secrets from local or remote disk images

Dump NTDS with golden certificates and UnPAC the hash

PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads

Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.