{"enrichment":{"faq":[{"a":"Windows Credential Harvesting is a tool designed to locate and extract credentials cached on Windows systems through registry queries, file searches, shadow copies, and DPAPI decryption. It covers browser passwords, saved sessions, unattend files, and vault entries accessible without domain access.","q":"What is Windows Credential Harvesting used for?"},{"a":"Windows Credential Harvesting extracts passwords by querying the Windows registry, searching file systems for credential stores, accessing shadow copies, and decrypting DPAPI-protected data. It targets browser password managers, saved RDP sessions, unattend configuration files, and Windows Credential Manager vault entries.","q":"How does Windows Credential Harvesting extract windows passwords?"},{"a":"Windows Credential Harvesting can harvest browser-stored passwords, cached login sessions, credentials in unattend files, Windows Credential Manager vault entries, and authentication tokens. It accesses these without requiring domain administrator privileges.","q":"What types of credentials can this tool harvest?"},{"a":"Yes, Windows Credential Harvesting supports post-exploitation activities by extracting harvested credentials that enable privilege escalation and lateral movement across networked systems. The extracted credentials can be reused to access additional resources and accounts.","q":"Can Windows Credential Harvesting enable lateral movement?"},{"a":"Windows Credential Harvesting is released under the GPL-3.0 license, which permits use, modification, and distribution under the terms of the GNU General Public License version 3.","q":"What is the license for Windows Credential Harvesting?"}],"shadow_tags":["post-exploitation","credential-theft","windows-security","privilege-escalation","lateral-movement","password-dumping","authentication-bypass","offensive-security"],"summary_rewrite":"Locate and extract credentials cached on Windows systems through registry queries, file searches, shadow copies, and DPAPI decryption. Covers browser passwords, saved sessions, unattend files, and vault entries accessible without domain access."},"gist":{"api_url":"https://skillfed.io/api/skills/blacklanternsecurity/red-run/windows-credential-harvesting.json","as_of":"2026-04-01","description":"Windows Credential Harvesting extracts locally stored credentials from compromised systems for authorized.","install":{"manual":["git clone https://github.com/blacklanternsecurity/red-run","cp -r red-run ~/.claude/skills/windows-credential-harvesting"],"primary":"npx skillfed install blacklanternsecurity/red-run/windows-credential-harvesting","version":"6272ab88"},"kind":"skill","mirror_url":"https://skillfed.io/blacklanternsecurity/red-run/windows-credential-harvesting.md","similar":[{"id":"blacklanternsecurity/red-run/windows-discovery","name":"Windows Discovery","publisher":"blacklanternsecurity/red-run","url":"https://skillfed.io/blacklanternsecurity/red-run/windows-discovery"},{"id":"yaklang/hack-skills/windows-privilege-escalation","name":"windows-privilege-escalation","publisher":"yaklang/hack-skills","url":"https://skillfed.io/yaklang/hack-skills/windows-privilege-escalation"},{"id":"blacklanternsecurity/red-run/windows-token-impersonation","name":"Windows Token Impersonation","publisher":"blacklanternsecurity/red-run","url":"https://skillfed.io/blacklanternsecurity/red-run/windows-token-impersonation"}],"title":"Windows Credential Harvesting by blacklanternsecurity \u2014 SkillFed","use":{"when":["Windows Credential Harvesting extracts passwords by querying the Windows registry, searching file systems for credential stores.","Windows Credential Harvesting can harvest browser-stored passwords, cached login sessions, credentials in unattend files."]},"what":{"lead":"Windows Credential Harvesting extracts locally stored credentials from compromised systems for authorized penetration testing.","rest":"Locate and extract credentials cached on Windows systems through registry queries, file searches, shadow copies, and DPAPI decryption. Covers browser passwords, saved sessions, unattend files, and vault entries accessible without domain access."}},"id":"blacklanternsecurity/red-run/windows-credential-harvesting","install":{"mode":"external","repo":"https://github.com/blacklanternsecurity/red-run"},"links":{"html":"https://skillfed.io/blacklanternsecurity/red-run/windows-credential-harvesting","md":"https://skillfed.io/blacklanternsecurity/red-run/windows-credential-harvesting.md","repo":"https://github.com/blacklanternsecurity/red-run"},"meta":{"agents_supported":[],"first_seen":"2026-07-28","forks":34,"language":"Python","last_updated":"2026-04-01","license":"GPL-3.0","name":"Windows Credential Harvesting","publisher":"blacklanternsecurity","stars":241},"relations":{"similar":[{"id":"zebbern/claude-code-guide/windows-privilege-escalation"},{"id":"blacklanternsecurity/red-run/windows-discovery"},{"id":"blacklanternsecurity/red-run/adcs-persistence"},{"id":"blacklanternsecurity/red-run/sccm-exploitation"},{"id":"Devin-AXIS/iPolloWork/daytona-windows-cert"},{"id":"different-ai/openwork/daytona-windows-cert"},{"id":"blacklanternsecurity/red-run/credential-dumping"},{"id":"yaklang/hack-skills/windows-privilege-escalation"},{"id":"obra/superpowers-lab/windows-vm"},{"id":"blacklanternsecurity/red-run/windows-token-impersonation"}]},"slug":{"owner":"blacklanternsecurity","repo":"red-run","skill":"windows-credential-harvesting"},"version":"6272ab88"}
