Commit Graph

99 Commits

Author SHA1 Message Date
Benjamin DELPY
e6924b75ed Compatible with Visual Studio 2015 2015-07-24 00:20:34 +02:00
Benjamin DELPY
c00b9cfab3 DPAPI vault IV for @dfirfpi 2015-07-21 04:11:25 +02:00
Benjamin DELPY
1265e86bfe README update for VS 2013 Express + user32.lib for mimilove 2015-07-19 17:10:43 +02:00
Benjamin DELPY
f686a7400d mimilove DC support (large table handle instead of small) 2015-07-19 15:15:31 +02:00
Benjamin DELPY
9bac6378c6 mimilove for Windows 2000 <3 2015-07-19 02:34:06 +02:00
Benjamin DELPY
5084e9d803 Thanks to @dfirfpi new samples, some cool adaptations! 2015-07-16 01:19:48 +02:00
Benjamin DELPY
f527ec2297 Removed unused var 'j' :) 2015-07-15 01:15:28 +02:00
Benjamin DELPY
3172c1dc23 DPAPI credentials (legacy & vault) 2015-07-15 01:13:21 +02:00
Benjamin DELPY
6aa1836e41 Kerberos tickets with External SID 2015-06-29 00:37:49 +02:00
Benjamin DELPY
67f7f8c466 DPAPI oe auto provisioning & DPAPI_SYSTEM memory reading 2015-06-26 01:22:02 +02:00
Benjamin DELPY
5766e29f33 DPAPI oe starting 2015-06-22 01:31:26 +02:00
Benjamin DELPY
81b9af79ef Unprotect CNG & CAPI from all keys 2015-06-19 01:19:01 +02:00
Benjamin DELPY
c622d6ae42 Fix on key export 2015-06-18 02:21:33 +02:00
Benjamin DELPY
841deedbf8 DPAPI for CAPI & CNG 2015-06-18 02:18:17 +02:00
Benjamin DELPY
bcac477384 DPAPI Masterkeys (normal, backup, domain) 2015-06-14 02:46:21 +02:00
Benjamin DELPY
60a71a7951 DPAPI & Crypto 2015-06-07 23:19:28 +02:00
Benjamin DELPY
552fe7ac51 Crypto and DPAPI cleaning 2015-06-03 02:13:43 +02:00
Benjamin DELPY
64ba9534ba LsaRetrievePrivateData without shellcode and support for remote via LSA RPC 2015-05-30 00:00:57 +02:00
Benjamin DELPY
8c783af863 PFX from key and certificate 2015-05-25 22:22:26 +02:00
Benjamin DELPY
45cade5b76 DPAPI Backup keys export from memory cache (sekurlsa + WinDBG), WinDBG LSAIso support 2015-05-25 00:24:46 +02:00
Benjamin DELPY
627041252b DPAPI Backup keys export 2015-05-23 23:49:04 +02:00
Benjamin DELPY
d7a76c08c8 Fix Yara :) 2015-05-16 00:14:22 +02:00
Benjamin DELPY
a36e552549 Yara: PowerShell with PE Reflective Injection 2015-05-15 23:24:29 +02:00
Benjamin DELPY
ee4ab682cf Small update to Yara rules 2015-05-14 13:53:04 +02:00
Benjamin DELPY
65e1249269 Yara rules 2015-05-10 22:15:08 +02:00
Benjamin DELPY
11d3376fd3 Some hash functions + one fix for SHA-1 on XP 2015-05-09 19:58:55 +02:00
Benjamin DELPY
5760bd8736 More LSA Isolation structures 2015-05-07 01:30:34 +02:00
Benjamin DELPY
723f6d9b43 lsadump decrypt fix, LSA Iso for Win10 2015-05-02 13:38:33 +02:00
Benjamin DELPY
e3914fec3a registry write access (limitations with low-level file access) 2015-05-01 23:29:39 +02:00
Benjamin DELPY
c7cf47f168 PAC fields, Crypto NT6 functions & Kiwi for Cache 2015-04-29 02:38:06 +02:00
Benjamin DELPY
d05eb826ac trust cache for WinDbg mimilib, fix for mimikatz 2015-04-19 21:21:05 +02:00
Benjamin DELPY
7923015d09 Domain trust keys, from NT6 cache and NTDS cache via RPC 2015-04-19 01:16:16 +02:00
Benjamin DELPY
55e292f895 Minor adaptation to Golden/Silver Tickers for Windows 2000 2015-04-16 00:20:43 +02:00
Benjamin DELPY
755bff14d8 Smartcard details for WinDbg + fix for 7x64 2015-04-06 22:41:15 +02:00
Benjamin DELPY
4ac9a1879e SmartCard informations, fixed PIN code decryption on Windows 2003 2015-04-06 12:21:50 +02:00
Benjamin DELPY
880b47218b krbtgt for WinDbg 2015-04-02 00:48:23 +02:00
Benjamin DELPY
83a8f4214d kvno for RODC, krbtgt in LSASS memory, fix un memory module for minidump 2015-04-01 00:09:09 +02:00
Benjamin DELPY
2a959729cb Local SID in SAM & SECURITY hive, Domain SID in SECURITY only 2015-03-20 15:46:07 +01:00
Benjamin DELPY
ab38babf93 Windows 10 Preview, driver & lsa minor fix + WinDbg 2015-03-12 01:46:03 +01:00
Benjamin DELPY
c4f9fc5639 Windows 10 Constant & LSA MSV1_0 module. Added Windows 2012 support for AddSid 2015-01-30 21:43:09 +01:00
Benjamin DELPY
a2cde2a2fc Crypto fix for Windows 8.0/2012 2015-01-22 22:22:41 +01:00
Benjamin DELPY
2d9e15bb83 Inspired by Skeleton 2015-01-17 01:23:41 +01:00
Benjamin DELPY
c85332baba minor file function change 2015-01-13 22:08:23 +01:00
Benjamin DELPY
4e798859ba Some fixes for mimidrv & crypto. Preparation for Windows 10. 2014-12-21 15:38:14 +01:00
Benjamin DELPY
253c460938 Console Output fixed for PowerShell/RunAs, ASN1 optimizations 2014-12-13 19:52:00 +01:00
Benjamin DELPY
155c3221f7 Some fixes for latest MS updates 2014-12-07 02:45:50 +01:00
Benjamin DELPY
baf7785c9e ntdll.min.lib adjusted for RtlAnsiStringToUnicodeString 2014-11-21 00:18:57 +01:00
Benjamin DELPY
f109700dab Merge pull request #5 from tazeat/master
I think @clymb3r will love you =)
Thank you very much for this var re-init!
2014-11-20 22:16:29 +01:00
brandoncasaba
cbb2f4bb0a Fix memory access violation when calling powershell_reflective_mimikatz more than once. 2014-11-20 12:53:26 -08:00
Benjamin DELPY
d5676aa66c minesweeper, Kerberos ccache, Windows 10 update, newsoft contre-rump, ... 2014-11-20 08:57:04 +01:00