offensive-tools/cracking/cain-and-abel/SKILL.md
Windows password recovery tool for sniffing, cracking (dictionary/brute-force/cryptanalysis), and decoding stored credentials. Use when recovering Windows hashes, cracking captured handshakes, or decoding cached credentials on Windows systems.
npx skillsauth add aeondave/malskill cain-and-abelInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Windows GUI password recovery — sniffer, hash cracker, credential decoder.
| Feature | Purpose | |---------|---------| | Sniffer | Capture network credentials (ARP poisoning) | | Cracker | Dictionary, brute-force, cryptanalysis of hashes | | Decoders | Decode stored passwords (LSA, VNC, dialup) | | Network | ARP poisoning, route discovery | | Wireless | WEP/WPA capture and crack | | Certificate | Certificate collector via MITM |
MD5, SHA-1, LM, NTLM, NTLMv2, MySQL, MS-SQL, Oracle, Cisco PIX/IOS, VNC, RADIUS, WPA.
Crack NTLM from SAM dump:
+ → Add NT hashes from SAMARP poison + credential capture:
Note: Use only on authorized systems. Cain & Abel triggers most AV.
| File | When to load |
|------|--------------|
| references/ | Hash import formats and dictionary sources |
development
Auth/lab ref: Unicorn Engine CPU-only emulation for shellcode, decryptors, custom VM handlers, instruction tracing, memory hooks, and register-level experiments.
development
Auth/lab ref: Renode board and SoC simulation for MCU/RTOS firmware, UART/GPIO/peripheral modeling, GDB remote debugging, REPL platforms, and RESC scripts.
development
Auth/lab ref: Qiling OS-layer binary emulation for PE/ELF/Mach-O/UEFI/shellcode with rootfs, syscall/API hooks, filesystem mapping, and runtime patching.
databases
Auth/lab ref: QEMU user-mode and full-system emulation for cross-arch binaries, firmware, kernels, disks, serial consoles, networking, and GDB stubs.