> For the complete documentation index, see [llms.txt](https://heinosass.gitbook.io/leet-sheet/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://heinosass.gitbook.io/leet-sheet/post-exploitation/untitled/dumping-passwords.md).

# Dumping Passwords

## **mimikatz**

You can dump passwords (or NTML hash with Windows >=8.1) with mimikatz. Meterpreter should help with that iirc.

## Impacket secretsdump&#x20;

Performs various techniques to dump hashes from the remote machine without executing any agent there.

{% embed url="<https://github.com/SecureAuthCorp/impacket/blob/master/examples/secretsdump.py>" %}

```
python3 secretsdump.py FULLY_QUALIFIED_DOMAIN_NAME/USERNAME:PASSWORD@IP_ADDRESS
```
