Quarks PwDump
Quarks PwDump is new open source tool to dump various types of Windows credentials:
It currently extracts :
- Local accounts NT/LM hashes + history
- Domain accounts NT/LM hashes + history
- Cached domain password
- Bitlocker recovery information (recovery passwords & key packages)
The tool is currently dedicated to work live on operating systems without injecting in any process, limiting the risk of undermining their integrity or stability. it requires administrator’s privileges and is still in beta test. http://code.google.com/p/quarkspwdump/ more info http://www.quarkslab.com/en-blog+read+13