DonPapi
Last updated
Last updated
My third favorite tool to retreive secrets of windows with linux is donPAPI, it is used to get dpapi and other passwords stored informations (files, browser, schedule tasks,…). This tool don’t touch LSASS so it is stealthier and work most of the time even if av and edr are enabled on the target.
Installation
Run ntlmrelayx.py and wait for a connecting for fernando.alonzo
Run Responder
DonPapi give us the stored password for the sql service sql_svc:YouWillNotKerboroast1ngMeeeeee
We also get the password of fernando.alonzo: IDr1R3allyF@sTF1! due to a scheduled task setup on this computer too.