Extract SAM hashes from compromised workstations - Extract NTDS.dit from the domain controller - Capture NTLMv2 hashes with Responder