Commit Graph

22 Commits

Author SHA1 Message Date
Benjamin DELPY
c07a5ce5c9 [new] mimikatz IIS module, to deal with passwords in applicationHost.config
[new/internal] tiny xml module (msxml2)
[internal] mimikatz::lsadump cast fix to build on v140
2016-07-11 00:32:51 +02:00
Benjamin DELPY
c4e64a9e6c [new] LSA private data can be retrieved with LsaRetrievePrivateData and now LsaQuerySecret 2016-06-25 21:31:25 +02:00
Benjamin DELPY
35b122908b Chrome DPAPI support & optimization
[new] dpapi::chrome, with custom/minimized sqlite3 included
[new] kerberos::ask now supports encryption preference (des/rc4/aes128/aes256)
[improvement] DRSR RPC code size minimized
[improvement] dpapi::wlan && dpapi::wwan use better functions to describe blobs
[internal] kull_m_string now supports q&d unicode to ascii
2016-06-23 02:16:36 +02:00
Benjamin DELPY
81594553f7 New SID module
[remove] misc::addsid
[new] sid:: module, to lookup, query, modify, add... (2003/2008r2/2012r2 right now)
2016-05-06 01:31:04 +02:00
Benjamin DELPY
9e298f16e4 Welcom to Windows 10 LTSB & current
[remove] mimidrv & mimikatz kernel module: Process & Object callbacks remover are not anymore in the program
[internal] Windows 10 is now splitted in 1507 (LTSB) and 1511 (current)
[internal] mimidrv: Windows 10 support added
[internal] mimilib WinDBG module & mimikatz::sekurlsa: Windows 10 MSV / Kerberos Tickets are not specific anymore (offsets table)
[internal] Using KULL_M_MEMORY_GLOBAL_OWN_HANDLE instead of local variable in each function
2016-03-27 19:22:36 +02:00
Benjamin DELPY
34d1d0f573 Crypto & Kerberos enhancements
- [fix] dpapi::capi now deals with AT_SIGNATURE keys
- [fix] sekurlsa::kerberos / kerberos:: encryption type are now signed
- [new] kerberos::ask to ask / save TGS from current TGT
- [new] crypto::system to describe/to export Windows System Certificate (cert, crl, ctl, keyid)
- [internal] smaller banner for smaller displays
- [internal] Copyrights for 2016
- [internal] kull_m_file can deal with environment-variable strings in paths
- [internal] kull_m_crypto new types for CERT_PROP_*_ID
2016-01-12 03:13:12 +01:00
Benjamin DELPY
fbb32cdcfa MSV & Kerberos fixes, LSA and Privilege enhancements
- [fix] sekurlsa::msv & mimilib for Windows 10 build 10586
- [fix #20] sekurlsa::tickets (display & export) for NT 6 != Windows 10
- [close #16] kerberos::golden now with ~NetBios name in LogonDomainName field of the PAC
- [new] privilege module shortcuts (driver, security, tcb, backup, restore) and functions (by id or name)
- [new] lsadump::dcsync and lsadump::lsa /inject 'NTLM-Strong-NTOWF' in Supplemental Credentials structures (Windows 2016 TP 4)
- [internal] NtSetSystemInformation can now be used in code
2016-01-06 02:46:28 +01:00
Benjamin DELPY
c322dc582f Cleaning & few Win10 adaptations 2015-08-30 22:01:05 +02:00
Benjamin DELPY
8b8eaf0201 Global licence update, credits to Vincent LE TOUX for DCSync, and lsadump::hash moved to crypto::hash 2015-08-25 11:19:01 +02:00
Benjamin DELPY
9c21b2f70d lsadump::dcsync cleaning (it frees the memory!), and domain autodetect 2015-08-13 01:11:27 +02:00
Benjamin DELPY
e6924b75ed Compatible with Visual Studio 2015 2015-07-24 00:20:34 +02:00
Benjamin DELPY
552fe7ac51 Crypto and DPAPI cleaning 2015-06-03 02:13:43 +02:00
Benjamin DELPY
64ba9534ba LsaRetrievePrivateData without shellcode and support for remote via LSA RPC 2015-05-30 00:00:57 +02:00
Benjamin DELPY
c4f9fc5639 Windows 10 Constant & LSA MSV1_0 module. Added Windows 2012 support for AddSid 2015-01-30 21:43:09 +01:00
Benjamin DELPY
c85332baba minor file function change 2015-01-13 22:08:23 +01:00
Benjamin DELPY
d5676aa66c minesweeper, Kerberos ccache, Windows 10 update, newsoft contre-rump, ... 2014-11-20 08:57:04 +01:00
Benjamin DELPY
5d191619fc Microsoft BlueHat edition
Windows 10 Technical Preview inside, but some kernel parts are missing
2014-10-10 01:53:03 -07:00
Benjamin DELPY
e6eead2053 Kerberos Golden Ticket AES 128/256 support 2014-06-10 01:42:19 +02:00
Benjamin DELPY
fd667773cb Pass-The-Hash enhancements, 'powerkatz', Kerberos keys better ouptut 2014-05-05 01:24:54 +02:00
Benjamin DELPY
568b71c590 Some cosmetic fixes (output, unicode detect, vault "pause", ...) 2014-04-25 02:03:55 +02:00
Benjamin DELPY
853ee232f0 Code cleaning & Base64 output 2014-04-23 22:00:29 +02:00
Benjamin DELPY
bb371c2acb Initial upload 2014-04-06 20:31:53 +02:00