> For the complete documentation index, see [llms.txt](https://gitbook.seguranca-informatica.pt/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://gitbook.seguranca-informatica.pt/credentials-exfiltration.md).

# Data Exfiltration

- [Extracting certs/private keys from Windows using mimikatz and intercepting calls with burpsuite](https://gitbook.seguranca-informatica.pt/credentials-exfiltration/extracting-certs-private-keys-from-windows-using-mimikatz-and-intercepting-calls-with-burpsuite.md): Extracting certs/private keys from certificates that disable private key exporting and use BurpSuite to intercept the requests.
- [Doppelganger: Cloning and Dumping LSASS (Win11)](https://gitbook.seguranca-informatica.pt/credentials-exfiltration/doppelganger-cloning-and-dumping-lsass-win11.md)
- [Recovery lsass.dmp from Defender Quarantine](https://gitbook.seguranca-informatica.pt/credentials-exfiltration/recovery-lsass.dmp-from-defender-quarantine.md): Decrypt Windows Defender quarantined files using Microsoft’s RC4 algorithm
