# OS Credentials

- [Windows & Active Directory](https://red.infiltr8.io/redteam/credentials/os-credentials/windows-and-active-directory.md): MITRE ATT\&CK™ OS Credential Dumping - Technique T1003
- [SAM & LSA secrets](https://red.infiltr8.io/redteam/credentials/os-credentials/windows-and-active-directory/sam-and-lsa-secrets.md): MITRE ATT\&CK™ Sub-techniques T1003.002, T1003.004 and T1003.005
- [DPAPI secrets](https://red.infiltr8.io/redteam/credentials/os-credentials/windows-and-active-directory/dpapi-protected-secrets.md): MITRE ATT\&CK™ Sub-technique T1555.003
- [NTDS secrets](https://red.infiltr8.io/redteam/credentials/os-credentials/windows-and-active-directory/ntds.md): MITRE ATT\&CK™ Sub-technique T1003.003
- [LSASS secrets](https://red.infiltr8.io/redteam/credentials/os-credentials/windows-and-active-directory/lsass.md): MITRE ATT\&CK™ Sub-technique T1003.001
- [DCSync](https://red.infiltr8.io/redteam/credentials/os-credentials/windows-and-active-directory/dcsync.md): MITRE ATT\&CK™ Sub-technique T1003.006
- [Kerberos key list](https://red.infiltr8.io/redteam/credentials/os-credentials/windows-and-active-directory/kerberos-key-list.md)
- [Group Policy Preferences](https://red.infiltr8.io/redteam/credentials/os-credentials/windows-and-active-directory/group-policies-preferences.md): MITRE ATT\&CK™ Sub-technique T1552.006
- [AutoLogon Registry](https://red.infiltr8.io/redteam/credentials/os-credentials/windows-and-active-directory/autologon-registry.md)
- [In-memory secrets](https://red.infiltr8.io/redteam/credentials/os-credentials/windows-and-active-directory/passwords-in-memory.md)
- [Cached Kerberos tickets](https://red.infiltr8.io/redteam/credentials/os-credentials/windows-and-active-directory/cached-kerberos-tickets.md): MITRE ATT\&CK™ Steal or Forge Kerberos Tickets - Technique T1558
- [Linux](https://red.infiltr8.io/redteam/credentials/os-credentials/linux.md)
- [Shadow File](https://red.infiltr8.io/redteam/credentials/os-credentials/linux/shadow-file.md): MITRE ATT\&CK™ OS Credential Dumping: /etc/passwd and /etc/shadow - Technique T1003.008
- [In-memory secrets](https://red.infiltr8.io/redteam/credentials/os-credentials/linux/passwords-in-memory.md): MITRE ATT\&CK™ OS Credential Dumping: Proc Filesystem - Technique T1003.007
- [Linux Cached Kerberos tickets](https://red.infiltr8.io/redteam/credentials/os-credentials/linux/cached-kerberos-tickets.md): MITRE ATT\&CK™ Steal or Forge Kerberos Tickets - Technique T1558
- [Samba LDB files](https://red.infiltr8.io/redteam/credentials/os-credentials/linux/samba-ldb-files.md)
- [Samba DCSync (Vampire)](https://red.infiltr8.io/redteam/credentials/os-credentials/linux/samba-dcsync-vampire.md)


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://red.infiltr8.io/redteam/credentials/os-credentials.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
