> For the complete documentation index, see [llms.txt](https://htb.linuxsec.org/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://htb.linuxsec.org/active-directory/credential-hunting.md).

# Credential Hunting

* [x] Group Policy Preferences
* [x] Powershell History
* [x] From Document Files
* [x] LaZagne / Mimikatz (elevated shell)
* [x] DPAPI Credential Dumping (NetExec, dploot)
