Skip to main contentSkip to main content
Room Banner
Back to all walkthroughs
Room Icon

Credentials Harvesting

Premium room

Apply current authentication models employed in modern environments to a red team approach.

medium

120 min

26,981

User profile photo.
User profile photo.

To access material, start machines and answer questions login.

Welcome to Credentials Harvesting

This room discusses the fundamental knowledge for red teamers taking advantage of obtained credentials to perform Lateral Movement and access resources within the environment. We will be showing how to obtain, reuse, and impersonate user credentials. 

Credential harvesting consists of techniques for obtaining credentials like login information, account names, and passwords. It is a technique of extracting credential information from a system in various locations such as clear-text files, registry, memory dumping, etc. 

As a red teamer, gaining access to legitimate credentials has benefits:

  • It can give access to systems (Lateral Movement).
  • It makes it harder to detect our actions.
  • It provides the opportunity to create and manage accounts to help achieve the end goals of a red team engagement.

Learning Objectives

  • Understand the method of extracting credentials from local windows (SAM database)
  • Learn how to access Windows memory and dump clear-text passwords and authentication tickets locally and remotely.
  • Introduction to Windows Credentials Manager and how to extract credentials.
  • Learn methods of extracting credentials for Domain Controller
  • Enumerate the Local Administrator Password Solution (LAPS) feature.
  • Introduction to attacks that lead to obtaining credentials.

Room Prerequisites

We strongly suggest finishing the following Active Directory rooms before diving into this room:

Answer the questions below
I have completed room prerequisites and am ready to learn about Credentials Harvesting!

Ready to learn Cyber Security?

The Credentials Harvesting room is only available for premium users. Signup now to access more than 500 free rooms and learn cyber security through a fun, interactive learning environment.

Already have an account? Log in

We use cookies to ensure you get the best user experience. For more information see our cookie policy.