T5AI for Cloud & Identity Attack Paths
Credential access and cracking
Once you have a foothold, credentials are the currency of escalation. Learn where Windows stores secrets, how attackers harvest them from LSASS, DPAPI and NTDS, and how offline cracking turns hashes into passwords.
Advanced4 min readprofessional streamUpdated Sat Aug 01 2026 00:00:00 GMT+0000 (Coordinated Universal Time)
Learning objectives
- Map the main Windows credential stores and the access each one requires.
- Distinguish harvesting a credential from cracking it, and know when cracking is even needed.
- Explain pass-the-hash and pass-the-ticket and why a captured hash is immediately useful.
- Use AI to triage harvested material while keeping every credential action behind human approval.
Academy subscription
Subscribe to unlock this module
This module is part of the StrikeOps Academy subscription. Unlock every paid module, with hands-on labs and knowledge checks.
- Every paid module across all tracks
- Hands-on labs and knowledge checks
- New content as it ships
$59/ month · or $590 / year
The Reference library and Foundation starters are free to read now.