Dumping and Cracking Hashes
After compromising a Local Administrator account, we can dump hashes from he SAM and LSA on the machine using secretsdump. This can be done using the accounts password or hash.
We can then crack the hashes using hashcat
On older machines that have wdigest enabled, there is a possibility to view passwords in clear-text