credhist

$ target-query <path/to/target> -f credhist
Details

Module

os.windows.credhist.CredHistPlugin

Output

records

Module documentation

Windows CREDHIST file parser.

Windows XP: C:\Documents and Settings\username\Application Data\Microsoft\Protect\CREDHIST Windows 7 and up: C:\Users\username\AppData\Roaming\Microsoft\Protect\CREDHIST

Resources:

Function documentation

Yield and decrypt all Windows CREDHIST entries on the target.