New to Claude Skills? Learn how to install them →

mukul975 on GitHub

Extracting Credentials from Memory Dump

Free

Recover credentials from Windows memory dumps efficiently.

Get this skill

Free · Opens the source repo

What Extracting Credentials from Memory Dump does

The Extracting Credentials from Memory Dump skill is designed for cybersecurity professionals engaged in incident response and memory forensics. Utilizing tools like Volatility 3, Mimikatz, and pypykatz, this skill enables users to extract sensitive information such as cached credentials, password hashes, Kerberos tickets, and authentication tokens from Windows memory dumps. This process is critical for understanding the scope of a security incident, especially when assessing what credentials an attacker may have accessed.

The skill guides users through a structured workflow that starts with verifying the integrity of a memory dump and identifying the operating system version. Following this, it provides detailed commands for extracting various types of credentials, including SAM database hashes and LSA secrets. The use of pypykatz allows for deeper analysis of the LSASS process memory, making it possible to recover not only NTLM hashes but also Kerberos tickets and other authentication materials.

This skill is particularly useful in scenarios where immediate action is required, such as determining which accounts need password resets after a breach or investigating lateral movement within a network. By extracting and analyzing credentials from memory dumps, security teams can quickly identify compromised accounts and take appropriate actions to mitigate risks.

However, users must have a solid understanding of Windows authentication mechanisms and the legal implications of performing such extractions. The skill requires specific prerequisites, including the installation of Volatility 3 and Mimikatz, as well as appropriate legal authorization to ensure compliance with laws governing data access and privacy.

When to use it

Use this skill during incident response to recover credentials from memory dumps, especially after a security breach.

When not to use it

This skill is not suitable for environments where legal authorization for credential extraction cannot be guaranteed or where memory dumps are not available.

What you can build with it

Incident Response After a Breach

Quickly extract credentials from a memory dump to assess what an attacker may have accessed.

Credential Compromise Assessment

Evaluate the scope of a credential compromise by analyzing extracted password hashes and tokens.

Lateral Movement Investigation

Identify accounts involved in pass-the-hash or pass-the-ticket attacks by recovering Kerberos tickets.

How to install Extracting Credentials from Memory Dump

View source

1. Install with the skills CLI

npx skills add mukul975/anthropic-cybersecurity-skills/extracting-credentials-from-memory-dump --agent claude-code

2. Or install it manually

Download the skill folder and drop it into ~/.claude/skills/ for all projects, or .claude/skills/ to scope it to one repo. Restart Claude Code so it picks up the new skill.

Anthropic's agentic coding CLI, and the reference implementation of Agent Skills. Drop a skill folder into ~/.claude/skills and Claude Code loads it automatically whenever a task matches the skill's description. Claude Code docs

Inside SKILL.md

Written by mukul975

Extracting Credentials from Memory Dump

When to Use

  • During incident response to determine what credentials an attacker had access to
  • When assessing the scope of credential compromise after a breach
  • For identifying accounts that need immediate password resets
  • When investigating lateral movement and pass-the-hash/pass-the-ticket attacks
  • For recovering encryption keys or authentication tokens from process memory

Prerequisites

  • Memory dump in raw, ELF, or crash dump format
  • Volatility 3 with Windows symbol tables
  • Mimikatz (for offline analysis of extracted LSASS dumps)
  • pypykatz (Python implementation of Mimikatz for Linux-based analysis)
  • Understanding of Windows authentication (NTLM, Kerberos, DPAPI)
  • Appropriate legal authorization for credential extraction

Workflow

Step 1: Prepare Tools and Verify Memory Dump

# Install analysis tools
pip install volatility3 pypykatz

# Verify memory dump integrity
sha256sum /cases/case-2024-001/memory/memory.raw

# Identify the OS version
vol -f /cases/case-2024-001/memory/memory.raw windows.info

# Verify LSASS process exists in memory
vol -f /cases/case-2024-001/memory/memory.raw windows.pslist | grep -i lsass

# Output:
# PID    PPID   ImageFileName   Offset(V)        Threads  Handles  SessionId
# 684    564    lsass.exe       0xffffe00123456   35       1234     0

Step 2: Extract Credential Hashes with Volatility

# Dump SAM database hashes from memory
vol -f /cases/case-2024-001/memory/memory.raw windows.hashdump \
   | tee /cases/case-2024-001/analysis/hashdump.txt

# Output format:
# User           RID    LM Hash                          NTLM Hash
# Administrator  500    aad3b435b51404eeaad3b435b51404ee  fc525c9683e8fe067095ba2ddc971889
# Guest          501    aad3b435b51404eeaad3b435b51404ee  31d6cfe0d16ae931b73c59d7e0c089c0
# DefaultAccount 503    aad3b435b51404eeaad3b435b51404ee  31d6cfe0d16ae931b73c59d7e0c089c0
# svcbackup      1001   aad3b435b51404eeaad3b435b51404ee  2b576acbe6bcfda7294d6bd18041b8fe

# Extract LSA secrets
vol -f /cases/case-2024-001/memory/memory.raw windows.lsadump \
   | tee /cases/case-2024-001/analysis/lsadump.txt

# Extract cached domain credentials
vol -f /cases/case-2024-001/memory/memory.raw windows.cachedump \
   | tee /cases/case-2024-001/analysis/cachedump.txt

Step 3: Dump LSASS Process Memory for Detailed Analysis

# Dump LSASS process memory (PID from Step 1)
vol -f /cases/case-2024-001/memory/memory.raw windows.memmap --pid 684 --dump \
   -o /cases/case-2024-001/analysis/lsass_dump/

# Alternative: Dump all files associated with LSASS
vol -f /cases/case-2024-001/memory/memory.raw windows.dumpfiles --pid 684 \
   -o /cases/case-2024-001/analysis/lsass_files/

# Use procdump plugin for cleaner process dump
vol -f /cases/case-2024-001/memory/memory.raw windows.dumpfiles \
   --pid 684 -o /cases/case-2024-001/analysis/

# Rename the dump file for pypykatz/mimikatz
mv /cases/case-2024-001/analysis/lsass_dump/pid.684.dmp \
   /cases/case-2024-001/analysis/lsass.dmp

Step 4: Extract Credentials with pypykatz

# Run pypykatz against the full memory dump
pypykatz lsa minidump /cases/case-2024-001/analysis/lsass.dmp \
   > /cases/case-2024-001/analysis/pypykatz_results.txt 2>&1

# Run pypykatz against the raw memory dump directly
pypykatz rekall /cases/case-2024-001/memory/memory.raw \
   > /cases/case-2024-001/analysis/pypykatz_full.txt 2>&1

# Parse pypykatz output for structured analysis
python3 << 'PYEOF'
import json

# pypykatz can also output JSON
import subprocess
result = subprocess.run(
    ['pypykatz', 'lsa', 'minidump', '/cases/case-2024-001/analysis/lsass.dmp', '-j'],
    capture_output=True, text=True
)

if result.stdout:
    data = json.loads(result.stdout)

    print("=== EXTRACTED CREDENTIALS ===\n")

    for session_key, session in data.get('logon_sessions', {}).items():
        username = session.get('username', 'Unknown')
        domain = session.get('domainname', '')
        logon_server = session.get('logon_server', '')
        logon_time = session.get('logon_time', '')
        sid = session.get('sid', '')

        if username and username != '(null)':
            print(f"Session: {domain}\\{username}")
            print(f"  SID: {sid}")
            print(f"  Logon Server: {logon_server}")
            print(f"  Logon Time: {logon_time}")

            # NTLM hashes
            msv = session.get('msv_creds', [])
            for cred in msv:
                nt = cred.get('NThash', '')
                lm = cred.get('LMHash', '')
                if nt:
                    print(f"  NTLM Hash: {nt}")
                if lm:
                    print(f"  LM Hash: {lm}")

            # Kerberos tickets
            kerb = session.get('kerberos_creds', [])
            for cred in kerb:
                password = cred.get('password', '')
                if password:
                    print(f"  Kerberos Password: {password}")
                tickets = cred.get('tickets', [])
                for ticket in tickets:
                    print(f"  Kerberos Ticket: {ticket.get('server', '')} (type: {ticket.get('enc_type', '')})")

            # WDigest (plaintext on older systems)
            wdigest = session.get('wdigest_creds', [])
            for cred in wdigest:
                pwd = cred.get('password', '')
                if pwd:
                    print(f"  WDigest Password: {pwd}")

            # DPAPI master keys
            dpapi = session.get('dpapi_creds', [])
            for cred in dpapi:
                mk = cred.get('masterkey', '')
                if mk:
                    print(f"  DPAPI Master Key: {mk[:40]}...")

            print()
PYEOF

Step 5: Extract Kerberos Tickets and Tokens

# Extract Kerberos tickets from memory
python3 << 'PYEOF'
import subprocess, json

result = subprocess.run(
    ['pypykatz', 'lsa', 'minidump', '/cases/case-2024-001/analysis/lsass.dmp', '-j', '-k', '/cases/case-2024-001/analysis/kerberos/'],
    capture_output=True, text=True
)

# pypykatz exports .kirbi files to the specified directory
import os
kirbi_dir = '/cases/case-2024-001/analysis/kerberos/'
if os.path.exists(kirbi_dir):
    for f in os.listdir(kirbi_dir):
        if f.endswith('.kirbi'):
            filepath = os.path.join(kirbi_dir, f)
            size = os.path.getsize(filepath)
            print(f"  Kerberos ticket: {f} ({size} bytes)")
PYEOF

# Search process memory for authentication tokens and API keys
vol -f /cases/case-2024-001/memory/memory.raw windows.strings --pid 684 | \
   grep -iE '(bearer |authorization:|api[_-]key|token=|password=|secret=)' \
   > /cases/case-2024-001/analysis/auth_strings.txt

# Search for cloud credentials in memory
vol -f /cases/case-2024-001/memory/memory.raw windows.strings | \
   grep -iE '(AKIA[A-Z0-9]{16}|ASIA[A-Z0-9]{16}|aws_secret_access_key)' \
   > /cases/case-2024-001/analysis/aws_credentials.txt

# Search for browser session tokens
vol -f /cases/case-2024-001/memory/memory.raw windows.strings | \
   grep -iE '(session_id=|PHPSESSID=|JSESSIONID=|_ga=|sid=)' \
   > /cases/case-2024-001/analysis/session_tokens.txt

Step 6: Compile Credential Findings Report

# Generate credential compromise assessment
python3 << 'PYEOF'
print("""
CREDENTIAL EXTRACTION REPORT
==============================
Case: 2024-001
Source: memory.raw (16 GB Windows 10 memory dump)
Analysis Date: 2024-01-20

COMPROMISED ACCOUNTS:
=====================

1. Local Accounts (SAM):
   - Administrator (RID 500): NTLM hash extracted
   - svcbackup (RID 1001): NTLM hash extracted
   - SQLService (RID 1002): NTLM hash extracted

2. Domain Accounts (LSASS):
   - CORP\\admin.user: NTLM hash + Kerberos TGT
   - CORP\\svc.backup: NTLM hash + plaintext password (WDigest)
   - CORP\\domain.admin: Kerberos TGS tickets for 3 services

3. Cached Domain Credentials:
   - CORP\\helpdesk.user: DCC2 hash
   - CORP\\it.manager: DCC2 hash

4. Cloud Credentials:
   - AWS Access Key: AKIA... found in process memory (PID 3456)
   - Azure AD token found in browser process memory

IMMEDIATE ACTIONS REQUIRED:
- Reset passwords for all listed accounts
- Revoke and rotate AWS access keys
- Invalidate all active Kerberos tickets (krbtgt reset)
- Review DPAPI-protected data for additional exposure
""")
PYEOF

Key Concepts

ConceptDescription
LSASS (Local Security Authority)Windows process managing authentication, storing credentials in memory
NTLM hashNT LAN Manager hash of user password used for authentication
Kerberos TGTTicket Granting Ticket allowing request of service tickets
WDigestLegacy authentication protocol storing plaintext passwords in memory (pre-Win8.1)
DPAPIData Protection API using master keys derived from user credentials
DCC2 (Domain Cached Credentials)Cached domain password hashes for offline logon
LSA SecretsEncrypted service account passwords and other secrets stored by LSA
Pass-the-HashAttack technique using extracted NTLM hashes without knowing the plaintext password

Tools & Systems

ToolPurpose
Volatility 3Memory forensics framework with hashdump, lsadump, cachedump plugins
pypykatzPython implementation of Mimikatz for cross-platform LSASS analysis
MimikatzWindows credential extraction tool (used offline against dumps)
secretsdump.pyImpacket tool for extracting secrets from SAM/SYSTEM/SECURITY
hashcatPassword hash cracking for recovered NTLM and DCC2 hashes
John the RipperAlternative password cracking tool
RubeusKerberos ticket manipulation and extraction tool
ImpacketPython toolkit for working with Windows network protocols and credentials

Common Scenarios

Scenario 1: Post-Breach Credential Assessment Extract all cached credentials from LSASS memory to determine which accounts were exposed, prioritize password resets based on privilege level, check for golden ticket material (krbtgt hash), assess if cloud credentials were accessible.

Scenario 2: Lateral Movement Investigation Extract NTLM hashes and Kerberos tickets to understand how the attacker moved between systems, identify pass-the-hash/pass-the-ticket artifacts, correlate extracted credentials with network logon events in event logs.

Scenario 3: Ransomware Operator Credential Theft Analyze pre-encryption memory dump for Mimikatz execution evidence, extract all available credential types, determine if domain admin credentials were obtained, assess if krbtgt was compromised (golden ticket), plan credential rotation strategy.

Scenario 4: Cloud Credential Theft from Endpoint Search endpoint memory for AWS access keys, Azure tokens, and GCP service account keys stored by CLI tools and browsers, identify exposed cloud permissions, immediately rotate discovered credentials, audit cloud audit logs for unauthorized access.

Output Format

Credential Extraction Summary:
  Source: memory.raw (16 GB, Windows 10 Build 19041)
  LSASS PID: 684

  Credentials Recovered:
    Local NTLM Hashes:        4 accounts
    Domain NTLM Hashes:       3 accounts
    Kerberos TGTs:             2 tickets
    Kerberos TGS:              5 service tickets
    Plaintext Passwords:       1 (WDigest - svc.backup)
    Cached Domain Creds:       2 DCC2 hashes
    LSA Secrets:               3 service account passwords
    DPAPI Master Keys:         4 keys recovered
    Cloud Credentials:         1 AWS access key, 1 Azure token

  Highest Privilege Compromised: Domain Admin (CORP\domain.admin)

  Recommended Actions:
    - Immediate: Reset all extracted account passwords
    - Immediate: Rotate AWS access key AKIA...
    - Urgent: Double krbtgt password reset (golden ticket mitigation)
    - High: Revoke all Kerberos tickets via krbtgt rotation
    - Medium: Audit DPAPI-protected data exposure

Frequently asked questions about Extracting Credentials from Memory Dump

Similar skills