Attempt to scrape cleartext credentials from the LSASS memory space: meterpreter > creds_all Use code with caution.
To ensure you can come back later, install a backdoor (only in a lab environment!).
Windows Remote Management (WinRM) can be a common attack surface on Windows targets, and this VM is misconfigured to accept default credentials.
mount -t cifs //192.168.56.105/ADMIN$ /mnt/target -o username=vagrant,password=vagrant