leftp / DPAPISnoop
A C# tool to output crackable DPAPI hashes from user MasterKeys
☆131Updated 2 months ago
Related projects ⓘ
Alternatives and complementary repositories for DPAPISnoop
- Find .net assemblies locally☆92Updated 2 years ago
- Get Fine Grained Password Policy☆65Updated 6 months ago
- Determine if the WebClient Service (WebDAV) is running on a remote system☆123Updated 8 months ago
- Lateral Movement via the .NET Profiler☆76Updated this week
- ☆94Updated last year
- ☆138Updated 2 years ago
- Investigation about ACL abusing for Active Directory Certificate Services (AD CS)☆119Updated 3 years ago
- ☆89Updated 2 years ago
- Programmatically start WebClient from an unprivileged session to enable that juicy privesc.☆66Updated last year
- Enumerate information from NTLM authentication enabled web endpoints 🔎☆35Updated last year
- HelpSystems Nanodump, but wrapped in powershell via Invoke-ReflectivePEInjection☆53Updated 2 years ago
- Source generator to add D/Invoke and indirect syscall methods to a C# project.☆170Updated 8 months ago
- C# version of NTLMRawUnHide☆72Updated 2 years ago
- ☆66Updated 3 months ago
- ☆83Updated 2 years ago
- Proof of Concept code and samples presenting emerging threat of MSI installer files.☆77Updated last year
- ☆77Updated last year
- Lateral Movement☆119Updated last year
- ☆61Updated 2 years ago
- Simple BOF to read the protection level of a process☆104Updated last year
- ☆73Updated 7 months ago
- ☆122Updated 11 months ago
- A collection of various and sundry code snippets that leverage .NET dynamic tradecraft☆135Updated 6 months ago
- Cobalt Strike BOF that identifies Attack Surface Reduction (ASR) rules, actions, and exclusion locations☆138Updated 8 months ago
- ☆68Updated last year
- Modified versions of the Cobalt Strike Process Injection Kit☆88Updated 10 months ago
- ☆83Updated 6 months ago
- Tool for playing with Windows Access Token manipulation.☆52Updated last year
- Cobalt Strike BOF for quser.exe implementation using Windows API☆83Updated last year
- A Python POC for CRED1 over SOCKS5☆134Updated last month