svchost.exe
Locate the svchost.exe process that's holding RDP creds:
Use ProcDump or comsvc.dll to dump process memory:
Grep for plaintext passwords:
Mimikatz
Last updated
Locate the svchost.exe process that's holding RDP creds:
Use ProcDump or comsvc.dll to dump process memory:
Grep for plaintext passwords:
Last updated