Benjamin DELPY
|
e6924b75ed
|
Compatible with Visual Studio 2015
|
2015-07-24 00:20:34 +02:00 |
|
Benjamin DELPY
|
c00b9cfab3
|
DPAPI vault IV for @dfirfpi
|
2015-07-21 04:11:25 +02:00 |
|
Benjamin DELPY
|
1265e86bfe
|
README update for VS 2013 Express + user32.lib for mimilove
|
2015-07-19 17:10:43 +02:00 |
|
Benjamin DELPY
|
f686a7400d
|
mimilove DC support (large table handle instead of small)
|
2015-07-19 15:15:31 +02:00 |
|
Benjamin DELPY
|
9bac6378c6
|
mimilove for Windows 2000 <3
|
2015-07-19 02:34:06 +02:00 |
|
Benjamin DELPY
|
5084e9d803
|
Thanks to @dfirfpi new samples, some cool adaptations!
|
2015-07-16 01:19:48 +02:00 |
|
Benjamin DELPY
|
f527ec2297
|
Removed unused var 'j' :)
|
2015-07-15 01:15:28 +02:00 |
|
Benjamin DELPY
|
3172c1dc23
|
DPAPI credentials (legacy & vault)
|
2015-07-15 01:13:21 +02:00 |
|
Benjamin DELPY
|
6aa1836e41
|
Kerberos tickets with External SID
|
2015-06-29 00:37:49 +02:00 |
|
Benjamin DELPY
|
67f7f8c466
|
DPAPI oe auto provisioning & DPAPI_SYSTEM memory reading
|
2015-06-26 01:22:02 +02:00 |
|
Benjamin DELPY
|
5766e29f33
|
DPAPI oe starting
|
2015-06-22 01:31:26 +02:00 |
|
Benjamin DELPY
|
81b9af79ef
|
Unprotect CNG & CAPI from all keys
|
2015-06-19 01:19:01 +02:00 |
|
Benjamin DELPY
|
c622d6ae42
|
Fix on key export
|
2015-06-18 02:21:33 +02:00 |
|
Benjamin DELPY
|
841deedbf8
|
DPAPI for CAPI & CNG
|
2015-06-18 02:18:17 +02:00 |
|
Benjamin DELPY
|
bcac477384
|
DPAPI Masterkeys (normal, backup, domain)
|
2015-06-14 02:46:21 +02:00 |
|
Benjamin DELPY
|
60a71a7951
|
DPAPI & Crypto
|
2015-06-07 23:19:28 +02:00 |
|
Benjamin DELPY
|
552fe7ac51
|
Crypto and DPAPI cleaning
|
2015-06-03 02:13:43 +02:00 |
|
Benjamin DELPY
|
64ba9534ba
|
LsaRetrievePrivateData without shellcode and support for remote via LSA RPC
|
2015-05-30 00:00:57 +02:00 |
|
Benjamin DELPY
|
8c783af863
|
PFX from key and certificate
|
2015-05-25 22:22:26 +02:00 |
|
Benjamin DELPY
|
45cade5b76
|
DPAPI Backup keys export from memory cache (sekurlsa + WinDBG), WinDBG LSAIso support
|
2015-05-25 00:24:46 +02:00 |
|
Benjamin DELPY
|
627041252b
|
DPAPI Backup keys export
|
2015-05-23 23:49:04 +02:00 |
|
Benjamin DELPY
|
d7a76c08c8
|
Fix Yara :)
|
2015-05-16 00:14:22 +02:00 |
|
Benjamin DELPY
|
a36e552549
|
Yara: PowerShell with PE Reflective Injection
|
2015-05-15 23:24:29 +02:00 |
|
Benjamin DELPY
|
ee4ab682cf
|
Small update to Yara rules
|
2015-05-14 13:53:04 +02:00 |
|
Benjamin DELPY
|
65e1249269
|
Yara rules
|
2015-05-10 22:15:08 +02:00 |
|
Benjamin DELPY
|
11d3376fd3
|
Some hash functions + one fix for SHA-1 on XP
|
2015-05-09 19:58:55 +02:00 |
|
Benjamin DELPY
|
5760bd8736
|
More LSA Isolation structures
|
2015-05-07 01:30:34 +02:00 |
|
Benjamin DELPY
|
723f6d9b43
|
lsadump decrypt fix, LSA Iso for Win10
|
2015-05-02 13:38:33 +02:00 |
|
Benjamin DELPY
|
e3914fec3a
|
registry write access (limitations with low-level file access)
|
2015-05-01 23:29:39 +02:00 |
|
Benjamin DELPY
|
c7cf47f168
|
PAC fields, Crypto NT6 functions & Kiwi for Cache
|
2015-04-29 02:38:06 +02:00 |
|
Benjamin DELPY
|
d05eb826ac
|
trust cache for WinDbg mimilib, fix for mimikatz
|
2015-04-19 21:21:05 +02:00 |
|
Benjamin DELPY
|
7923015d09
|
Domain trust keys, from NT6 cache and NTDS cache via RPC
|
2015-04-19 01:16:16 +02:00 |
|
Benjamin DELPY
|
55e292f895
|
Minor adaptation to Golden/Silver Tickers for Windows 2000
|
2015-04-16 00:20:43 +02:00 |
|
Benjamin DELPY
|
755bff14d8
|
Smartcard details for WinDbg + fix for 7x64
|
2015-04-06 22:41:15 +02:00 |
|
Benjamin DELPY
|
4ac9a1879e
|
SmartCard informations, fixed PIN code decryption on Windows 2003
|
2015-04-06 12:21:50 +02:00 |
|
Benjamin DELPY
|
880b47218b
|
krbtgt for WinDbg
|
2015-04-02 00:48:23 +02:00 |
|
Benjamin DELPY
|
83a8f4214d
|
kvno for RODC, krbtgt in LSASS memory, fix un memory module for minidump
|
2015-04-01 00:09:09 +02:00 |
|
Benjamin DELPY
|
2a959729cb
|
Local SID in SAM & SECURITY hive, Domain SID in SECURITY only
|
2015-03-20 15:46:07 +01:00 |
|
Benjamin DELPY
|
ab38babf93
|
Windows 10 Preview, driver & lsa minor fix + WinDbg
|
2015-03-12 01:46:03 +01:00 |
|
Benjamin DELPY
|
c4f9fc5639
|
Windows 10 Constant & LSA MSV1_0 module. Added Windows 2012 support for AddSid
|
2015-01-30 21:43:09 +01:00 |
|
Benjamin DELPY
|
a2cde2a2fc
|
Crypto fix for Windows 8.0/2012
|
2015-01-22 22:22:41 +01:00 |
|
Benjamin DELPY
|
2d9e15bb83
|
Inspired by Skeleton
|
2015-01-17 01:23:41 +01:00 |
|
Benjamin DELPY
|
c85332baba
|
minor file function change
|
2015-01-13 22:08:23 +01:00 |
|
Benjamin DELPY
|
4e798859ba
|
Some fixes for mimidrv & crypto. Preparation for Windows 10.
|
2014-12-21 15:38:14 +01:00 |
|
Benjamin DELPY
|
253c460938
|
Console Output fixed for PowerShell/RunAs, ASN1 optimizations
|
2014-12-13 19:52:00 +01:00 |
|
Benjamin DELPY
|
155c3221f7
|
Some fixes for latest MS updates
|
2014-12-07 02:45:50 +01:00 |
|
Benjamin DELPY
|
baf7785c9e
|
ntdll.min.lib adjusted for RtlAnsiStringToUnicodeString
|
2014-11-21 00:18:57 +01:00 |
|
Benjamin DELPY
|
f109700dab
|
Merge pull request #5 from tazeat/master
I think @clymb3r will love you =)
Thank you very much for this var re-init!
|
2014-11-20 22:16:29 +01:00 |
|
brandoncasaba
|
cbb2f4bb0a
|
Fix memory access violation when calling powershell_reflective_mimikatz more than once.
|
2014-11-20 12:53:26 -08:00 |
|
Benjamin DELPY
|
d5676aa66c
|
minesweeper, Kerberos ccache, Windows 10 update, newsoft contre-rump, ...
|
2014-11-20 08:57:04 +01:00 |
|