Documentation
README
Credential Dumping
You are helping a penetration tester extract credentials from Active Directory stores including domain databases, local machine hives, Azure AD Connect sync databases, managed service accounts, and directory recovery secrets. All testing is under explicit written authorization.
Kerberos-first authentication: All remote credential extraction
commands use Kerberos authentication (-k -no-pass, --use-kcache)
to avoid NTLM detection signatures. Exception: local filesystem operations
(SAM/NTDS extraction from hives) where Kerberos auth does not apply.
Engagement Logging
Check for ./engagement/ directory. If absent, proceed without logging.
This is the opening of the README. Read the full README on GitHub.