githubEdit

Network shares & mount virtual hard disks

  • Snafflerarrow-up-right (it searches for interesting files such as "pass" phrase in the file name, keePass database field, SSH keys, web.config, and many more.

Mount vmkd on linux

guestmount -a SQL01-disk1.vmdk -i --ro /mnt/vmdk

Mount vhd/vhdx on linux

guestmount --add WEBSRV10.vhdx  --ro /mnt/vhdx/ -m /dev/sda1

Disk management utility can be used as well

Dump hashes from backup virtual hard disk(vhd)

C:\Windows\System32\Config #(hash location) 
secretsdump.py -sam SAM -security SECURITY -system SYSTEM LOCAL

Last updated