Benjamin DELPY
|
ae041e0ece
|
lsadump::dcsync - XP and 2003 don't allow QueryContextAttributes for SECPKG_ATTR_SESSION_KEY when using NTLM protocol in userland, forcing Kerberos instead (Negociate otherwise).
Thanks @asolino for letting me show!
|
2015-08-24 12:21:52 +02:00 |
|
Benjamin DELPY
|
b2687e3085
|
DRSR error printing
|
2015-08-24 01:57:20 +02:00 |
|
Benjamin DELPY
|
bdab94dfff
|
DRSR fixes
|
2015-08-23 22:50:21 +02:00 |
|
Benjamin DELPY
|
a3c105af16
|
lsadump::dcsync and net::user updates
|
2015-08-17 00:18:04 +02:00 |
|
Benjamin DELPY
|
9c21b2f70d
|
lsadump::dcsync cleaning (it frees the memory!), and domain autodetect
|
2015-08-13 01:11:27 +02:00 |
|
Benjamin DELPY
|
7717b7a717
|
DCSync in mimikatz & for XP/2003
|
2015-08-11 01:27:13 +02:00 |
|
Benjamin DELPY
|
e6924b75ed
|
Compatible with Visual Studio 2015
|
2015-07-24 00:20:34 +02:00 |
|
Benjamin DELPY
|
c00b9cfab3
|
DPAPI vault IV for @dfirfpi
|
2015-07-21 04:11:25 +02:00 |
|
Benjamin DELPY
|
9bac6378c6
|
mimilove for Windows 2000 <3
|
2015-07-19 02:34:06 +02:00 |
|
Benjamin DELPY
|
5084e9d803
|
Thanks to @dfirfpi new samples, some cool adaptations!
|
2015-07-16 01:19:48 +02:00 |
|
Benjamin DELPY
|
3172c1dc23
|
DPAPI credentials (legacy & vault)
|
2015-07-15 01:13:21 +02:00 |
|
Benjamin DELPY
|
5766e29f33
|
DPAPI oe starting
|
2015-06-22 01:31:26 +02:00 |
|
Benjamin DELPY
|
81b9af79ef
|
Unprotect CNG & CAPI from all keys
|
2015-06-19 01:19:01 +02:00 |
|
Benjamin DELPY
|
841deedbf8
|
DPAPI for CAPI & CNG
|
2015-06-18 02:18:17 +02:00 |
|
Benjamin DELPY
|
bcac477384
|
DPAPI Masterkeys (normal, backup, domain)
|
2015-06-14 02:46:21 +02:00 |
|
Benjamin DELPY
|
60a71a7951
|
DPAPI & Crypto
|
2015-06-07 23:19:28 +02:00 |
|
Benjamin DELPY
|
552fe7ac51
|
Crypto and DPAPI cleaning
|
2015-06-03 02:13:43 +02:00 |
|
Benjamin DELPY
|
45cade5b76
|
DPAPI Backup keys export from memory cache (sekurlsa + WinDBG), WinDBG LSAIso support
|
2015-05-25 00:24:46 +02:00 |
|
Benjamin DELPY
|
627041252b
|
DPAPI Backup keys export
|
2015-05-23 23:49:04 +02:00 |
|
Benjamin DELPY
|
11d3376fd3
|
Some hash functions + one fix for SHA-1 on XP
|
2015-05-09 19:58:55 +02:00 |
|
Benjamin DELPY
|
e3914fec3a
|
registry write access (limitations with low-level file access)
|
2015-05-01 23:29:39 +02:00 |
|
Benjamin DELPY
|
c7cf47f168
|
PAC fields, Crypto NT6 functions & Kiwi for Cache
|
2015-04-29 02:38:06 +02:00 |
|
Benjamin DELPY
|
7923015d09
|
Domain trust keys, from NT6 cache and NTDS cache via RPC
|
2015-04-19 01:16:16 +02:00 |
|
Benjamin DELPY
|
83a8f4214d
|
kvno for RODC, krbtgt in LSASS memory, fix un memory module for minidump
|
2015-04-01 00:09:09 +02:00 |
|
Benjamin DELPY
|
c85332baba
|
minor file function change
|
2015-01-13 22:08:23 +01:00 |
|
Benjamin DELPY
|
253c460938
|
Console Output fixed for PowerShell/RunAs, ASN1 optimizations
|
2014-12-13 19:52:00 +01:00 |
|
Benjamin DELPY
|
155c3221f7
|
Some fixes for latest MS updates
|
2014-12-07 02:45:50 +01:00 |
|
Benjamin DELPY
|
d5676aa66c
|
minesweeper, Kerberos ccache, Windows 10 update, newsoft contre-rump, ...
|
2014-11-20 08:57:04 +01:00 |
|
Benjamin DELPY
|
5d191619fc
|
Microsoft BlueHat edition
Windows 10 Technical Preview inside, but some kernel parts are missing
|
2014-10-10 01:53:03 -07:00 |
|
Benjamin DELPY
|
f38ba31789
|
Kerberos keys hash generator, command line buffer extension
|
2014-09-28 21:47:26 +02:00 |
|
Benjamin DELPY
|
aac3e32edd
|
Coffee, Process fix, SidHistory & SpAcceptCredentials hook
|
2014-09-14 21:09:48 +02:00 |
|
Benjamin DELPY
|
7f7fcea319
|
mimidrv fix for image notify 7 x86, cd command & README update
|
2014-09-07 18:40:32 +02:00 |
|
Benjamin DELPY
|
63dec2f4d4
|
remotelib module update
|
2014-08-31 18:49:49 +02:00 |
|
Benjamin DELPY
|
6c753a74d6
|
DPAPI fix + Service "force" (>= Windows 7)
|
2014-08-30 21:56:18 +02:00 |
|
Benjamin DELPY
|
e6eead2053
|
Kerberos Golden Ticket AES 128/256 support
|
2014-06-10 01:42:19 +02:00 |
|
Benjamin DELPY
|
8ca8f056d2
|
Kernel Memory handle with mimidrv & vault fix
|
2014-06-07 21:24:10 +02:00 |
|
Benjamin DELPY
|
4ad7bbf38e
|
ARRAYSIZE & indentation
|
2014-05-28 18:00:36 +02:00 |
|
Benjamin DELPY
|
38be0f72a6
|
Fix stricmp for VS platforms
|
2014-05-26 08:06:48 +02:00 |
|
Benjamin DELPY
|
3843e998a8
|
lsadump::lsa /inject updated to avoid DLL injection, only code.
|
2014-05-25 21:37:38 +02:00 |
|
Benjamin DELPY
|
54502be4ca
|
lsadump::lsa can play with AD supplementalCredentials, with mimilib.dll
|
2014-05-24 22:16:46 +02:00 |
|
Benjamin DELPY
|
58b14945db
|
Pass-The-eKeys for 7/8 with KB2871997
|
2014-05-18 21:56:43 +02:00 |
|
Benjamin DELPY
|
8d83d5ab93
|
Structures for KB2871997 ;)
|
2014-05-14 01:41:25 +02:00 |
|
Benjamin DELPY
|
c509bbfbf7
|
Pass-The-Hash now supports AES keys for Kerberos with Windows 8.1/2012r2
|
2014-05-08 01:08:06 +02:00 |
|
Benjamin DELPY
|
fd667773cb
|
Pass-The-Hash enhancements, 'powerkatz', Kerberos keys better ouptut
|
2014-05-05 01:24:54 +02:00 |
|
Benjamin DELPY
|
5571133a4b
|
Kerberos 'Pass-The-Hash', eKeys
MSV 'Pass-The-Hash' improvements
Better Crypto output
README update
|
2014-04-30 23:01:08 +02:00 |
|
Benjamin DELPY
|
568b71c590
|
Some cosmetic fixes (output, unicode detect, vault "pause", ...)
|
2014-04-25 02:03:55 +02:00 |
|
Benjamin DELPY
|
106b6f4fd0
|
Base64 filename in header
|
2014-04-23 22:40:12 +02:00 |
|
Benjamin DELPY
|
9347714eb1
|
Fix CryptBinaryToString flags for Windows XP/2003
|
2014-04-23 22:13:24 +02:00 |
|
Benjamin DELPY
|
853ee232f0
|
Code cleaning & Base64 output
|
2014-04-23 22:00:29 +02:00 |
|
Benjamin DELPY
|
bb371c2acb
|
Initial upload
|
2014-04-06 20:31:53 +02:00 |
|