👾 Overview

Windows autologin credentials are used to have a machine automatically login without entering credentials on boot. This is commonly used in conjunction with Kiosk Mode to allow a machine to automatically launch kiosk mode as a given user.

These credentials are stored within the registry, they can be encrypted or stored in plaintext.

🔍 Discovery

If working with a kiosk, you’ll first need to break out. Open regedit and browse to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon.