What can an attacker recover from a Windows memory image after gaining access to an endpoint?
In my new blog, I explored:
WinPmem → Volatility 3 → SYSTEM/SAM → NTLM
#RedTeam #OffensiveSecurity
SE Sec Note @secnote · 2.88K subscribers 
In my new blog, I explored:
WinPmem → Volatility 3 → SYSTEM/SAM → NTLM