> For the complete documentation index, see [llms.txt](https://pentest.mxhx.org/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://pentest.mxhx.org/07-win-privesc/5-looting.md).

# 5 Looting

## After system/admin:

1. Go for sam dump on windows using reg.exe <https://xapax.github.io/security/#attacking_active_directory_domain/active_directory_privilege_escalation/credential_extraction/#extract-credentials-from-sam-and-security-hives-from-registry>
2. REF:
   1. <https://github.com/mubix/post-exploitation-wiki>
