Posts

Showing posts with the label mimikatz

Autordpwn V4.5 - The Shadow Assail Framework

Image
AutoRDPwn is a script created inwards Powershell as well as designed to automate the Shadow assault on Microsoft Windows computers. This vulnerability allows a remote aggressor to stance his victim's desktop without his consent, as well as fifty-fifty command it on request. For its right operation, it is necessary to comply alongside the requirements described inwards the user guide. Requirements Powershell 5.0 or higher Changes Version 4.5 • New ninja agency icon! • Automatic cleaning of Powershell history afterward execution • Now all dependencies are downloaded from the same repository • Many errors as well as bugs fixed • UAC & AMSI bypass inwards 64-bit systems • New module available: Remote Desktop Caching • New module available: Disable arrangement logs (Invoke-Phant0m) • New module available: Sticky Keys Hacking • New available module: Remote Desktop History • New available attack: Session Hijacking (passwordless) WARNING! This assault is real ...

Autordpwn V4.8 - The Shadow Ready On Framework

Image
AutoRDPwn is a script created inwards Powershell in addition to designed to automate the Shadow ready on on Microsoft Windows computers. This vulnerability allows a remote assaulter to persuasion his victim's desktop without his consent, in addition to fifty-fifty command it on request. For its right operation, it is necessary to comply alongside the requirements described inwards the user guide. Requirements Powershell 4.0 or higher Changes Version 4.8 • Compatibility alongside Powershell 4.0 • Automatic re-create of the content to the clipboard (passwords, hashes, dumps, etc.) • Automatic exclusion inwards Windows Defender (4 dissimilar methods) • Remote execution without password for PSexec, WMI in addition to Invoke-Command • New available attack: DCOM Passwordless Execution • New available module: Remote Access / Metasploit Web Delivery • New module available: Remote VNC Server (designed for legacy environments) • Autocomplete the host, user in addition t...

Winpwn - Automation For Internal Windows Penetrationtest

Image
In many past times internal penetration tests I frequently had problems alongside the existing Powershell Recon / Exploitation scripts due to missing proxy support. For this argue I wrote my ain script alongside automatic proxy recognition in addition to integration. The script is to a greater extent than frequently than non based on well-known large other offensive safety Powershell projects. I exclusively charge them 1 after the other into RAM via IEX Downloadstring in addition to partially automate the execution to salve time. Yes it is non a C# in addition to it may hold out flagged past times antivirus solutions. Windows Defender for illustration blocks merely about of the known scripts/functions. Different local recon modules, domain recon modules, pivilege escalation in addition to exploitation modules. Any suggestions, feedback in addition to comments are welcome! Just Import the Modules alongside "Import-Module .\WinPwn_v0.7.ps1" or alongside iex (new-object n...

Silketw - Flexible C# Wrapper For Etw (Event Tracing For Windows)

Image
SilkETW is a flexible C# wrapper for ETW , it is meant to abstract away the complexities of ETW as well as hand people a unproblematic interface to perform interrogation as well as introspection. While SilkETW has obvious defensive (and offensive) applications it is primarily a interrogation tool inwards it's electrical current state. For slow consumption, output information is serialized to JSON. The JSON information tin either live analyzed locally using PowerShell or shipped off to tertiary political party infrastructure such every bit Elasticsearch . Implementation Details Libraries SilkETW is buit on .Net v4.5 as well as uses a disclose of tertiary political party libraries, every bit shown below. Please run across LICENSE-3RD-PARTY for farther details. ModuleId Version LicenseUrl -------- ------- ---------- ...

Flashsploit - Exploitation Framework For Attiny85 Based Hid Attacks

Image
Flashsploit is an Exploitation Framework for Attacks using ATtiny85 HID Devices such equally Digispark USB Development Board, flashsploit generates Arduino IDE Compatible (.ino) Scripts based on User Input together with thence Starts a Listener inwards Metasploit-Framework if Required past times the Script, inwards Summary : Automatic Script Generation amongst Automated msfconsole. Features TODO : Add Linux together with OSX Scripts Windows Data Exfiltration Extract all WiFi Passwords together with Uploads an XML to SFTP Server: Extract Network Configuration Information of Target System together with Uploads to SFTP Server: Extract Passwords together with Other Critical Information using Mimikatz together with Uploads to SFTP Server: Reverse Shells Get Reverse Shell past times Abusing Microsoft HTML Apps (mshta): Get Reverse Shell past times Abusing Certification Authority Utility (certutil) Get Reverse Shell past times Abusing Windows ...