.. / CredDumpWithoutMimilkatz
Star

The lsass Process while great, is no where neaar the only way to dump credintials from windows. One of which is access the three registry hives: SAM, SYSTEM, and SECURITY. This is a method that can be used to dump credentials without mimikatz as well as offer some potenial stealth.

Command: Copy References:

https://www.ired.team/offensive-security/credential-access-and-credential-dumping

https://www.synacktiv.com/en/publications/lsa-secrets-revisiting-secretsdump