Commit Graph

79 Commits

Author SHA1 Message Date
Benjamin DELPY
627041252b DPAPI Backup keys export 2015-05-23 23:49:04 +02:00
Benjamin DELPY
d7a76c08c8 Fix Yara :) 2015-05-16 00:14:22 +02:00
Benjamin DELPY
a36e552549 Yara: PowerShell with PE Reflective Injection 2015-05-15 23:24:29 +02:00
Benjamin DELPY
ee4ab682cf Small update to Yara rules 2015-05-14 13:53:04 +02:00
Benjamin DELPY
65e1249269 Yara rules 2015-05-10 22:15:08 +02:00
Benjamin DELPY
11d3376fd3 Some hash functions + one fix for SHA-1 on XP 2015-05-09 19:58:55 +02:00
Benjamin DELPY
5760bd8736 More LSA Isolation structures 2015-05-07 01:30:34 +02:00
Benjamin DELPY
723f6d9b43 lsadump decrypt fix, LSA Iso for Win10 2015-05-02 13:38:33 +02:00
Benjamin DELPY
e3914fec3a registry write access (limitations with low-level file access) 2015-05-01 23:29:39 +02:00
Benjamin DELPY
c7cf47f168 PAC fields, Crypto NT6 functions & Kiwi for Cache 2015-04-29 02:38:06 +02:00
Benjamin DELPY
d05eb826ac trust cache for WinDbg mimilib, fix for mimikatz 2015-04-19 21:21:05 +02:00
Benjamin DELPY
7923015d09 Domain trust keys, from NT6 cache and NTDS cache via RPC 2015-04-19 01:16:16 +02:00
Benjamin DELPY
55e292f895 Minor adaptation to Golden/Silver Tickers for Windows 2000 2015-04-16 00:20:43 +02:00
Benjamin DELPY
755bff14d8 Smartcard details for WinDbg + fix for 7x64 2015-04-06 22:41:15 +02:00
Benjamin DELPY
4ac9a1879e SmartCard informations, fixed PIN code decryption on Windows 2003 2015-04-06 12:21:50 +02:00
Benjamin DELPY
880b47218b krbtgt for WinDbg 2015-04-02 00:48:23 +02:00
Benjamin DELPY
83a8f4214d kvno for RODC, krbtgt in LSASS memory, fix un memory module for minidump 2015-04-01 00:09:09 +02:00
Benjamin DELPY
2a959729cb Local SID in SAM & SECURITY hive, Domain SID in SECURITY only 2015-03-20 15:46:07 +01:00
Benjamin DELPY
ab38babf93 Windows 10 Preview, driver & lsa minor fix + WinDbg 2015-03-12 01:46:03 +01:00
Benjamin DELPY
c4f9fc5639 Windows 10 Constant & LSA MSV1_0 module. Added Windows 2012 support for AddSid 2015-01-30 21:43:09 +01:00
Benjamin DELPY
a2cde2a2fc Crypto fix for Windows 8.0/2012 2015-01-22 22:22:41 +01:00
Benjamin DELPY
2d9e15bb83 Inspired by Skeleton 2015-01-17 01:23:41 +01:00
Benjamin DELPY
c85332baba minor file function change 2015-01-13 22:08:23 +01:00
Benjamin DELPY
4e798859ba Some fixes for mimidrv & crypto. Preparation for Windows 10. 2014-12-21 15:38:14 +01:00
Benjamin DELPY
253c460938 Console Output fixed for PowerShell/RunAs, ASN1 optimizations 2014-12-13 19:52:00 +01:00
Benjamin DELPY
155c3221f7 Some fixes for latest MS updates 2014-12-07 02:45:50 +01:00
Benjamin DELPY
baf7785c9e ntdll.min.lib adjusted for RtlAnsiStringToUnicodeString 2014-11-21 00:18:57 +01:00
Benjamin DELPY
f109700dab Merge pull request #5 from tazeat/master
I think @clymb3r will love you =)
Thank you very much for this var re-init!
2014-11-20 22:16:29 +01:00
brandoncasaba
cbb2f4bb0a Fix memory access violation when calling powershell_reflective_mimikatz more than once. 2014-11-20 12:53:26 -08:00
Benjamin DELPY
d5676aa66c minesweeper, Kerberos ccache, Windows 10 update, newsoft contre-rump, ... 2014-11-20 08:57:04 +01:00
Benjamin DELPY
5d191619fc Microsoft BlueHat edition
Windows 10 Technical Preview inside, but some kernel parts are missing
2014-10-10 01:53:03 -07:00
Benjamin DELPY
f38ba31789 Kerberos keys hash generator, command line buffer extension 2014-09-28 21:47:26 +02:00
Benjamin DELPY
8c4eb572bb Silver ticket is here! TGS builder 2014-09-27 09:52:45 +02:00
Benjamin DELPY
8f6d69a041 misc::addsid now for 2008 R2 too 2014-09-20 00:31:06 +02:00
Benjamin DELPY
aac3e32edd Coffee, Process fix, SidHistory & SpAcceptCredentials hook 2014-09-14 21:09:48 +02:00
Benjamin DELPY
7f7fcea319 mimidrv fix for image notify 7 x86, cd command & README update 2014-09-07 18:40:32 +02:00
Benjamin DELPY
63dec2f4d4 remotelib module update 2014-08-31 18:49:49 +02:00
Benjamin DELPY
6c753a74d6 DPAPI fix + Service "force" (>= Windows 7) 2014-08-30 21:56:18 +02:00
Benjamin DELPY
4a71ae001b Kerberos Golden Ticket "renewmax" 2014-08-15 03:04:11 +02:00
Benjamin DELPY
6642607af5 New arguments for Golden Ticket : /endin:600 /renewin:10080 /startoffset:-10 (by example) 2014-08-09 21:13:52 -07:00
Benjamin DELPY
d65b0e7290 Kerberos purge fix + BlackHat / Defcon edition ;) 2014-07-20 23:39:39 +02:00
Benjamin DELPY
d752b84f47 Fix Kerberos free memory. Inject golden ticket from memory instead file (oe.eo) 2014-06-14 19:29:00 +02:00
Benjamin DELPY
e6eead2053 Kerberos Golden Ticket AES 128/256 support 2014-06-10 01:42:19 +02:00
Benjamin DELPY
efecbdc841 Fix Kernel ping 2014-06-07 21:40:13 +02:00
Benjamin DELPY
8ca8f056d2 Kernel Memory handle with mimidrv & vault fix 2014-06-07 21:24:10 +02:00
Benjamin DELPY
4ad7bbf38e ARRAYSIZE & indentation 2014-05-28 18:00:36 +02:00
Benjamin DELPY
38be0f72a6 Fix stricmp for VS platforms 2014-05-26 08:06:48 +02:00
Benjamin DELPY
21f1e25cc9 x64 srv lib no more needed 2014-05-25 21:40:31 +02:00
Benjamin DELPY
317d59779e x86 srv lib no more needed 2014-05-25 21:40:17 +02:00
Benjamin DELPY
08896a30f8 sekurlsalib no more needed 2014-05-25 21:39:41 +02:00