Benjamin DELPY
|
734e3f0291
|
[new] misc:sccm to decrypt SC_UserAccount credentials when SCCM private key access
|
2021-05-11 20:34:56 +02:00 |
Benjamin DELPY
|
fa42ed93aa
|
[new] mimikatz lsadump::postzerologon, to reinit DC password both in local store and AD
[change] https instead of http for blog :)
|
2020-09-17 03:17:11 +02:00 |
Benjamin DELPY
|
d07283a20d
|
[new] dpapi::create, to create (minimalist) Masterkeys file from a raw key
[internal] kull_m_token to deal with own SID et check if local or domain
|
2020-03-08 13:38:11 +01:00 |
Benjamin DELPY
|
b098bf37cf
|
[new] dpapi::chrome supports AES-256-GCM decryption for new Logins & Cookies
[new] dpapi::cred & vault::cred now supports double DPAPI for INET & Ivanti credentials
|
2020-02-08 12:42:34 +01:00 |
Benjamin DELPY
|
6972319852
|
[new] dpapi::masterkey now supports derivation from NTLM hash for protected user (/protected) instead of password
|
2020-01-23 10:12:22 +01:00 |
Benjamin DELPY
|
3c81f16b5b
|
New DPAPI stuff & crypto
[new] dpapi::masterkey now supports SID with SYSTEM_DPAPI (for @dirkjanm services ;))
[new] dpapi::cache filter non relevant SIDs
[new] dpapi::cred now supports WinInet double DPAPI
[new] dpapi::blob /raw for hex input
[new] dpapi::blob /ascii to force ascii output (when not unicode data)
[new] crypto:: & dpapi::cng key & certificates flags from current SDK (VSM)
[new] sr98::nedap module (@iceman1001 <3)
[new] lsadump::mbc to dump MachineBoundCertificate
|
2019-11-25 03:03:09 +01:00 |
Benjamin DELPY
|
3d8be22fff
|
[fix] a lots of @vletoux errors checking ;)
|
2018-02-06 00:16:51 +01:00 |
Benjamin DELPY
|
568c53e913
|
DPAPI Masterkey domain key can now be decrypted by RPC
[new] dpapi::masterkey ... /rpc [/domain:a.local] [/dc:srv.a.local]
[new] MS-BKRP RPC module
[new / internal] kull_m_rpc: generic RPC module
|
2016-06-25 01:51:50 +02:00 |
Benjamin DELPY
|
e15b0ca68a
|
Some DPAPI stuff
- [new] vault module now handles more Vault types, Attributes and Properties (with /attributes)
- [new] misc::compressme to create a compressed version of mimikatz
- [new] dpapi::cred now handles legacy (NT5) multiple credentials
- [new] dpapi::wifi & dpapi::wwan to deal with network profiles
- [internal] kuhl_m_vault: vault::list now deals with SID / credentials attributes (with one incorrect align.)
- [internal] kull_m_string: removed unused kull_m_string_suspectUnicodeStringStructure
- [internal] kull_m_string: added kull_m_string_printSuspectUnicodeString
- [internal] kull_m_string: added dirty kull_m_string_quickxml_simplefind
- [internal] kull_m_memory: quick compress & decompress routines
- [internal] kull_m_dpapi: added blob flags descriptions
- [internal] kull_m_dpapi: fixed blob protection flags description for system
- [internal] kull_m_dpapi: removed unused kull_m_dpapi_unprotect_backupkey_with_secret
- [internal] kull_m_cred: added legacy (NT5) credentials structures & routines
|
2016-02-08 01:41:26 +01:00 |
Benjamin DELPY
|
c322dc582f
|
Cleaning & few Win10 adaptations
|
2015-08-30 22:01:05 +02:00 |
Benjamin DELPY
|
8b8eaf0201
|
Global licence update, credits to Vincent LE TOUX for DCSync, and lsadump::hash moved to crypto::hash
|
2015-08-25 11:19:01 +02:00 |
Benjamin DELPY
|
3172c1dc23
|
DPAPI credentials (legacy & vault)
|
2015-07-15 01:13:21 +02:00 |
Benjamin DELPY
|
5766e29f33
|
DPAPI oe starting
|
2015-06-22 01:31:26 +02:00 |
Benjamin DELPY
|
81b9af79ef
|
Unprotect CNG & CAPI from all keys
|
2015-06-19 01:19:01 +02:00 |
Benjamin DELPY
|
841deedbf8
|
DPAPI for CAPI & CNG
|
2015-06-18 02:18:17 +02:00 |
Benjamin DELPY
|
bcac477384
|
DPAPI Masterkeys (normal, backup, domain)
|
2015-06-14 02:46:21 +02:00 |
Benjamin DELPY
|
60a71a7951
|
DPAPI & Crypto
|
2015-06-07 23:19:28 +02:00 |
Benjamin DELPY
|
552fe7ac51
|
Crypto and DPAPI cleaning
|
2015-06-03 02:13:43 +02:00 |
Benjamin DELPY
|
d5676aa66c
|
minesweeper, Kerberos ccache, Windows 10 update, newsoft contre-rump, ...
|
2014-11-20 08:57:04 +01:00 |