[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fDnIZDMbOgfsKhudpCfSu0ikLrqEJI8DQGFtn4DaoKaQ":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},515,"How does the Credential Manager differ between Windows 7 and Windows 8+ from a penetration testing perspective?","Starting from Windows 8, the Credential Manager interface was redesigned and added a separate 'Web Credentials' vault for credentials saved by Internet Explorer. Windows 7 does not have this distinction and instead has a 'Prompt for permission' option that can block automated extraction. Testers should be aware that the Get‑VaultCredential.ps1 script works on Win8+ for IE‑stored credentials, while on Windows 7, other methods like mimikatz or Invoke‑WCMDump may be needed. Understanding these differences is crucial during [information retrieval from Windows Credential Manager](\u002Fnews\u002Fpenetration-techniques-information-retrieval-from-windows-credential-manager).","\u003Cp>Starting from Windows 8, the Credential Manager interface was redesigned and added a separate &#39;Web Credentials&#39; vault for credentials saved by Internet Explorer. Windows 7 does not have this distinction and instead has a &#39;Prompt for permission&#39; option that can block automated extraction. Testers should be aware that the Get‑VaultCredential.ps1 script works on Win8+ for IE‑stored credentials, while on Windows 7, other methods like mimikatz or Invoke‑WCMDump may be needed. Understanding these differences is crucial during [information retrieval from Windows Credential Manager](\u002Fnews\u002Fpenetration-techniques-information-retrieval-from-windows-credential-manager).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-information-retrieval-from-windows-credential-manager\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-does-the-credential-manager-differ-between-windows-7-and-windows-8-from-a-pe-1777483275208","Windows 7, Windows 8, Credential Manager, Web Credentials, penetration testing differences",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},127,"Penetration Techniques - Information Retrieval from Windows Credential Manager","penetration-techniques-information-retrieval-from-windows-credential-manager","Learn how to retrieve plaintext passwords from Windows Credential Manager during penetration testing, covering domain and generic credentials with practical methods.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>During the post-exploitation phase, after gaining access, it is necessary to collect information from the target system. The more comprehensive the information, the more it aids in further penetration.\u003C\u002Fp>\u003Cp>For Windows systems, the Credential Manager contains crucial information.\u003C\u002Fp>\u003Cp>What specific types of information does it include, and what methods are available for retrieval? This article will introduce them one by one.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Different types of credentials in Credential Manager\u003C\u002Fli>\u003Cli>Methods for retrieving plaintext passwords of different credentials\u003C\u002Fli>\u003Cli>Practical testing\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to Credential Manager\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Credential Manager, translated as Credential Manager in Chinese, is used to store credentials (such as usernames and passwords for website logins and remote host connections).\u003C\u002Fp>\u003Cp>If users choose to store credentials, the system will automatically fill in the credentials when they perform corresponding operations again, enabling automatic login.\u003C\u002Fp>\u003Cp>Credentials are saved in a specific location known as the vault (located at %localappdata%\u002FMicrosoft\\Vault).\u003C\u002Fp>\u003Ch3>Credential categories:\u003C\u002Fh3>\u003Cp>There are two types: Domain Credentials and Generic Credentials.\u003C\u002Fp>\u003Ch4>Domain Credentials:\u003C\u002Fh4>\u003Cp>Only the local Local Security Authority (LSA) can read and write to them.\u003C\u002Fp>\u003Cp>This means that normal permissions cannot read the plaintext passwords of Domain Credentials.\u003C\u002Fp>\u003Ch4>Generic Credentials:\u003C\u002Fh4>\u003Cp>Can be read and written by user processes.\u003C\u002Fp>\u003Cp>This means that normal permissions can read the plaintext passwords of Generic Credentials.\u003C\u002Fp>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Faa380517.aspx\u003C\u002Fp>\u003Ch2>0x03 Practical Testing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Test 1:\u003C\u002Fh3>\u003Cp>Test System: Win7\u003C\u002Fp>\u003Cp>Access file share \\\\192.168.62.130\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017975541_0_1b71a9606f.jpeg\">\u003C\u002Fp>\u003Cp>Enter the correct username and password, select 'Remember my credentials'\u003C\u002Fp>\u003Cp>Next time when accessing, there is no need to enter the username and password again\u003C\u002Fp>\u003Cp>Added credentials can be found through Control Panel at Control Panel - User Accounts and Family Safety - Credential Manager\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017985885_1_e9ea7c116b.jpeg\">\u003C\u002Fp>\u003Cp>Password is encrypted and cannot be viewed directly\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The credential type for file sharing defaults to Domain Credentials\u003C\u002Fp>\u003Ch3>Test 2:\u003C\u002Fh3>\u003Cp>Test System: Win8\u003C\u002Fp>\u003Cp>Use IE browser to access the website https:\u002F\u002Fgithub.com\u002F, after successful login, choose to save the username and password\u003C\u002Fp>\u003Cp>Access the Credential Manager through the Control Panel, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017990321_2_9352d75499.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Starting from Win8, the Credential Manager interface has been redesigned (different from Win7), adding Web Credentials\u003C\u002Fp>\u003Cp>Displaying credential passwords requires entering the current username and password, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017994620_3_f62e7f912c.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The credential type for Internet Explorer defaults to Generic Credentials\u003C\u002Fp>\u003Ch3>Test 3:\u003C\u002Fh3>\u003Cp>Test system: Win7\u003C\u002Fp>\u003Cp>Add a generic credential through the Control Panel, with Internet or network address as Generi1, username as test1, and password as pass1, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017998074_4_3d28be61ac.jpeg\">\u003C\u002Fp>\u003Cp>The plaintext password of this generic credential cannot be obtained through the Control Panel\u003C\u002Fp>\u003Ch2>0x04 Exporting Plaintext Passwords from Credentials\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Obtain basic information of system credentials\u003C\u002Fh3>\u003Ch4>Tool 1: vaultcmd (built-in Windows system)\u003C\u002Fh4>\u003Cp>Common commands:\u003C\u002Fp>\u003Cp>List vaults:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vaultcmd \u002Flist\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Different types of credentials are stored under different vaults\u003C\u002Fp>\u003Cp>List vault summary, credential names and GUIDs:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vaultcmd \u002Flistschema\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>GUID corresponds to files under the path %localappdata%\u002FMicrosoft\\Vault\\{GUID}, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018001578_5_00a2f27cc1.jpeg\">\u003C\u002Fp>\u003Cp>List all credential information under the vault named \"Web Credentials\":\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vaultcmd \u002Flistcreds:\"Web Credentials\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If using a Chinese operating system, you can replace the name with the corresponding GUID using the following command:\u003C\u002Fp>\u003Cp>List all credentials under the vault with GUID {4BF4C442-9B8A-41A0-B380-DD4A704DDB28}:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vaultcmd \u002Flistcreds:{4BF4C442-9B8A-41A0-B380-DD4A704DDB28}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>List the properties of the vault with GUID {4BF4C442-9B8A-41A0-B380-DD4A704DDB28}, including file location, number of credentials contained, and protection method:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vaultcmd \u002Flistproperties:{4BF4C442-9B8A-41A0-B380-DD4A704DDB28}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>Tool 2: cmdkey\u003C\u002Fh4>\u003Cp>Entering cmdkey \u002Flist in the command line can list the Windows credentials in the system.\u003C\u002Fp>\u003Ch3>2. Obtain the plaintext password of Domain Credentials\u003C\u002Fh3>\u003Cp>Tool: mimikatz\u003C\u002Fp>\u003Cp>Parameter:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sekurlsa::logonpasswords\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Corresponding to the previous\u003Cstrong>Test 1\u003C\u002Fstrong>, displayed at the credman location, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018007474_6_d45593f5ab.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>mimikatz can not only export plaintext passwords of Domain Credentials but also plaintext passwords of the Generic Credentials type, but it cannot export plaintext passwords of the Generic Credentials type saved by the IE browser.\u003C\u002Fp>\u003Ch3>3. Obtain plaintext passwords of Generic Credentials\u003C\u002Fh3>\u003Ch4>(1) Generic Credentials saved by the IE browser\u003C\u002Fh4>\u003Cp>Tool: Get-VaultCredential.ps1\u003C\u002Fp>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FExfiltration\u002FGet-VaultCredential.ps1\u003C\u002Fp>\u003Cp>Corresponding to the previous\u003Cstrong>Test 2\u003C\u002Fstrong>The plaintext password was successfully exported on the Win8 system, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018010464_7_d104db6de0.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This script can also obtain credential information under the vault named Windows Credential, but it cannot obtain the plaintext password of the credentials.\u003C\u002Fp>\u003Cp>\u003Cstrong>Supplement:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The Credential Manager in the Win7 system differs from Win8, with an additional option to prompt for permission when a program uses this password, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018012654_8_1726850852.jpeg\">\u003C\u002Fp>\u003Cp>When selected, a prompt will appear (cannot be bypassed) when using PowerShell scripts to read plaintext passwords, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018014343_9_98a29ec065.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Other types of regular tickets\u003C\u002Fh4>\u003Cp>Tool: Invoke-WCMDump.ps1\u003C\u002Fp>\u003Cp>Download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fpeewpw\u002FInvoke-WCMDump\u002Fblob\u002Fmaster\u002FInvoke-WCMDump.ps1\u003C\u002Fp>\u003Cp>Corresponding to\u003Cstrong>Test 3\u003C\u002Fstrong>, regular user permissions are sufficient to export plaintext passwords of regular tickets, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018015607_10_d0aec0d0f8.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This script can also export Domain Credentials information (excluding plaintext passwords)\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces methods for obtaining plaintext passwords of various types of credentials, tests multiple tools, and helps everyone better understand this content.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>During the post-exploitation phase, after gaining access, it is necessary to collect information from the target system. The more comprehensive the information, the more it aids in further penetration.\u003C\u002Fp>\u003Cp>For Windows systems, the Credential Manager contains crucial information.\u003C\u002Fp>\u003Cp>What specific types of information does it include, and what methods are available for retrieval? This article will introduce them one by one.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Different types of credentials in Credential Manager\u003C\u002Fli>\u003Cli>Methods for retrieving plaintext passwords of different credentials\u003C\u002Fli>\u003Cli>Practical testing\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to Credential Manager\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Credential Manager, translated as Credential Manager in Chinese, is used to store credentials (such as usernames and passwords for website logins and remote host connections).\u003C\u002Fp>\u003Cp>If users choose to store credentials, the system will automatically fill in the credentials when they perform corresponding operations again, enabling automatic login.\u003C\u002Fp>\u003Cp>Credentials are saved in a specific location known as the vault (located at %localappdata%\u002FMicrosoft\\Vault).\u003C\u002Fp>\u003Ch3>Credential categories:\u003C\u002Fh3>\u003Cp>There are two types: Domain Credentials and Generic Credentials.\u003C\u002Fp>\u003Ch4>Domain Credentials:\u003C\u002Fh4>\u003Cp>Only the local Local Security Authority (LSA) can read and write to them.\u003C\u002Fp>\u003Cp>This means that normal permissions cannot read the plaintext passwords of Domain Credentials.\u003C\u002Fp>\u003Ch4>Generic Credentials:\u003C\u002Fh4>\u003Cp>Can be read and written by user processes.\u003C\u002Fp>\u003Cp>This means that normal permissions can read the plaintext passwords of Generic Credentials.\u003C\u002Fp>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Faa380517.aspx\u003C\u002Fp>\u003Ch2>0x03 Practical Testing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Test 1:\u003C\u002Fh3>\u003Cp>Test System: Win7\u003C\u002Fp>\u003Cp>Access file share \\\\192.168.62.130\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017975541_0_1b71a9606f-1.jpeg\">\u003C\u002Fp>\u003Cp>Enter the correct username and password, select 'Remember my credentials'\u003C\u002Fp>\u003Cp>Next time when accessing, there is no need to enter the username and password again\u003C\u002Fp>\u003Cp>Added credentials can be found through Control Panel at Control Panel - User Accounts and Family Safety - Credential Manager\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017985885_1_e9ea7c116b-1.jpeg\">\u003C\u002Fp>\u003Cp>Password is encrypted and cannot be viewed directly\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The credential type for file sharing defaults to Domain Credentials\u003C\u002Fp>\u003Ch3>Test 2:\u003C\u002Fh3>\u003Cp>Test System: Win8\u003C\u002Fp>\u003Cp>Use IE browser to access the website https:\u002F\u002Fgithub.com\u002F, after successful login, choose to save the username and password\u003C\u002Fp>\u003Cp>Access the Credential Manager through the Control Panel, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017990321_2_9352d75499-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Starting from Win8, the Credential Manager interface has been redesigned (different from Win7), adding Web Credentials\u003C\u002Fp>\u003Cp>Displaying credential passwords requires entering the current username and password, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017994620_3_f62e7f912c-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The credential type for Internet Explorer defaults to Generic Credentials\u003C\u002Fp>\u003Ch3>Test 3:\u003C\u002Fh3>\u003Cp>Test system: Win7\u003C\u002Fp>\u003Cp>Add a generic credential through the Control Panel, with Internet or network address as Generi1, username as test1, and password as pass1, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017998074_4_3d28be61ac-1.jpeg\">\u003C\u002Fp>\u003Cp>The plaintext password of this generic credential cannot be obtained through the Control Panel\u003C\u002Fp>\u003Ch2>0x04 Exporting Plaintext Passwords from Credentials\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Obtain basic information of system credentials\u003C\u002Fh3>\u003Ch4>Tool 1: vaultcmd (built-in Windows system)\u003C\u002Fh4>\u003Cp>Common commands:\u003C\u002Fp>\u003Cp>List vaults:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vaultcmd \u002Flist\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Different types of credentials are stored under different vaults\u003C\u002Fp>\u003Cp>List vault summary, credential names and GUIDs:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vaultcmd \u002Flistschema\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>GUID corresponds to files under the path %localappdata%\u002FMicrosoft\\Vault\\{GUID}, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018001578_5_00a2f27cc1-1.jpeg\">\u003C\u002Fp>\u003Cp>List all credential information under the vault named \"Web Credentials\":\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vaultcmd \u002Flistcreds:\"Web Credentials\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If using a Chinese operating system, you can replace the name with the corresponding GUID using the following command:\u003C\u002Fp>\u003Cp>List all credentials under the vault with GUID {4BF4C442-9B8A-41A0-B380-DD4A704DDB28}:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vaultcmd \u002Flistcreds:{4BF4C442-9B8A-41A0-B380-DD4A704DDB28}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>List the properties of the vault with GUID {4BF4C442-9B8A-41A0-B380-DD4A704DDB28}, including file location, number of credentials contained, and protection method:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>vaultcmd \u002Flistproperties:{4BF4C442-9B8A-41A0-B380-DD4A704DDB28}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>Tool 2: cmdkey\u003C\u002Fh4>\u003Cp>Entering cmdkey \u002Flist in the command line can list the Windows credentials in the system.\u003C\u002Fp>\u003Ch3>2. Obtain the plaintext password of Domain Credentials\u003C\u002Fh3>\u003Cp>Tool: mimikatz\u003C\u002Fp>\u003Cp>Parameter:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sekurlsa::logonpasswords\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Corresponding to the previous\u003Cstrong>Test 1\u003C\u002Fstrong>, displayed at the credman location, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018007474_6_d45593f5ab-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>mimikatz can not only export plaintext passwords of Domain Credentials but also plaintext passwords of the Generic Credentials type, but it cannot export plaintext passwords of the Generic Credentials type saved by the IE browser.\u003C\u002Fp>\u003Ch3>3. Obtain plaintext passwords of Generic Credentials\u003C\u002Fh3>\u003Ch4>(1) Generic Credentials saved by the IE browser\u003C\u002Fh4>\u003Cp>Tool: Get-VaultCredential.ps1\u003C\u002Fp>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FExfiltration\u002FGet-VaultCredential.ps1\u003C\u002Fp>\u003Cp>Corresponding to the previous\u003Cstrong>Test 2\u003C\u002Fstrong>The plaintext password was successfully exported on the Win8 system, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018010464_7_d104db6de0-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This script can also obtain credential information under the vault named Windows Credential, but it cannot obtain the plaintext password of the credentials.\u003C\u002Fp>\u003Cp>\u003Cstrong>Supplement:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The Credential Manager in the Win7 system differs from Win8, with an additional option to prompt for permission when a program uses this password, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018012654_8_1726850852-1.jpeg\">\u003C\u002Fp>\u003Cp>When selected, a prompt will appear (cannot be bypassed) when using PowerShell scripts to read plaintext passwords, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018014343_9_98a29ec065-1.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Other types of regular tickets\u003C\u002Fh4>\u003Cp>Tool: Invoke-WCMDump.ps1\u003C\u002Fp>\u003Cp>Download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fpeewpw\u002FInvoke-WCMDump\u002Fblob\u002Fmaster\u002FInvoke-WCMDump.ps1\u003C\u002Fp>\u003Cp>Corresponding to\u003Cstrong>Test 3\u003C\u002Fstrong>, regular user permissions are sufficient to export plaintext passwords of regular tickets, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018015607_10_d0aec0d0f8-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This script can also export Domain Credentials information (excluding plaintext passwords)\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces methods for obtaining plaintext passwords of various types of credentials, tests multiple tools, and helps everyone better understand this content.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1063,"Onedaysec",4,"published","2026-02-02T07:51:00.064Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Windows Credential Manager Penetration: Retrieving Plaintext Passwords","Windows Credential Manager, penetration testing, plaintext passwords, credential retrieval, post-exploitation, vaultcmd, domain credentials, generic credentials",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46,47],514,513,512,511,{"title":39,"description":39,"image":39},"2026-07-24T15:37:12.948Z","2026-07-23T16:01:40.683Z","draft","2026-07-23T16:12:54.827Z"]