Files
atomic-red-team/Windows/Credential_Access/Credentials_in_Files.md
T
Michael Haag e22d823c4b Credentials in Files
+ Credentials in Files
+ add Get-GPPPassword.ps1
+ Update matrix
2017-11-02 11:53:28 -07:00

13 lines
335 B
Markdown

# Credentials in Files
MITRE ATT&CK Technique: [T1081](https://attack.mitre.org/wiki/Technique/T1081)
## Group Policy Preference
[Payload](Payloads/Get-GPPPassword.ps1)
[PowerSploit Source](https://github.com/PowerShellMafia/PowerSploit/blob/master/Exfiltration/Get-GPPPassword.ps1)
Input:
Get-GPPPassword -Server EXAMPLE.COM