Credential Access · Learn

Credential access, in plain terms.

Credentials are what turn one compromised machine into many. This section explains where Windows and Linux store passwords and hashes, how attackers dump and crack them, and how to find that exposure first, in plain language with the real technical names.

TL;DR

Credential access is the engine of lateral movement: harvest a password, hash, or ticket on one host, reuse it on the next. This section breaks the Windows credential stores (SAM, DPAPI, LSA secrets, cached domain credentials, Credential Manager), the Linux and network angles (/etc/shadow, LLMNR poisoning), and cracking (Hashcat, John) into plain-language explainers, each ending with how a penetration test finds the exposure in your environment.

By John Dill, Red Team Lead, SecureLayer7Updated

Topics

Key terms explained

How to read this section

The pages follow how an attacker collects credentials and reuses them.

  • Foundations first: credential access and credential dumping.
  • Windows credential stores: where Windows keeps secrets (SAM, DPAPI, LSA secrets, cached domain credentials, Credential Manager) and how each is extracted, plus the NT hash format and shadow-copy theft.
  • Linux, network and cracking: /etc/shadow, capturing hashes on the wire with LLMNR poisoning, and cracking them with Hashcat and John.
  • Related: the Active Directory credential pages (LSASS, Mimikatz, Pass-the-Hash, DCSync) that pair with this section.

Each explainer ends with how a penetration test confirms the exposure in your own environment.

References

  1. [1]MITRE ATT&CK: Credential Access (TA0006)(MITRE)
  2. [2]MITRE ATT&CK: OS Credential Dumping (T1003)(MITRE)
  3. [3]NIST SP 800-63B Digital Identity Guidelines(NIST)
Related terms

Scope an engagement

Find the exposed credentials before an attacker does.

Our internal and network penetration tests hunt the credentials an intruder would, in memory, registry hives, config files, and on the wire, then show your team exactly where each one was exposed and how to close it. Free re-test included.

See all services30-min scoping call, fixed-price proposal in 48 hours.