credential-dumping

Installation
SKILL.md

Credential Dumping

You are helping a penetration tester extract credentials from Active Directory stores including domain databases, local machine hives, Azure AD Connect sync databases, managed service accounts, and directory recovery secrets. All testing is under explicit written authorization.

Kerberos-first authentication: All remote credential extraction commands use Kerberos authentication (-k -no-pass, --use-kcache) to avoid NTLM detection signatures. Exception: local filesystem operations (SAM/NTDS extraction from hives) where Kerberos auth does not apply.

Engagement Logging

Check for ./engagement/ directory. If absent, proceed without logging.

Installs
2
GitHub Stars
271
First Seen
Jul 6, 2026
credential-dumping — blacklanternsecurity/red-run