bwatters
57c882cab5
Land #18604 , Add Post Windows Gather to perform Mikrotik Winbox "Keep Password" credentials extraction
...
Merge branch 'land-18604' into upstream-master
2024-01-09 15:38:35 -06:00
Jack Heysel
3bad98afc6
Land #18488 , add kerberos_tickets post module
...
Adds a module to manage kerberos tickets from a compromised
host. This PR also includes rail gun enhancements.
2023-12-07 19:12:48 -05:00
siddolo
32e5dfb12d
Windows gather credentials for Mikrotik Winbox 'Keep Password' feature
2023-12-07 13:14:37 +01:00
Jemmy Wang
893da00c6a
Modify Table DisplayName and password matching regex
2023-11-09 13:58:14 +08:00
Jemmy Wang
9c23f86d83
Add support for v15 new encryption algorithm
2023-11-09 05:08:27 +08:00
Jemmy Wang
d4166098a8
Update to be compatible for PL/SQL 14
2023-11-08 01:15:22 +08:00
Spencer McIntyre
54bce7fcb5
Add module docs
2023-10-27 12:47:19 -04:00
Jemmy Wang
93c13ad6a7
Apply document suggestions from code review
...
Co-authored-by: jheysel-r7 <Jack_Heysel@rapid7.com >
2023-10-27 02:02:00 +08:00
Jemmy Wang
d07ad325b2
Add document for PL/SQL Developer gather credential module
2023-10-26 19:38:52 +08:00
h00die
557a15a115
spelling fixes on docs
2023-10-10 14:46:18 -04:00
Ashley Donaldson
6e438d338e
Modify execute_dotnet_assembly to run in existing processes (including our own process) and receive output.
2023-06-21 12:04:09 +10:00
Spencer McIntyre
d8870d7876
Address msftidy_docs complaints
2023-06-08 14:52:57 -04:00
attl4s
ec948b5c16
add documentation
2023-06-06 10:04:57 +02:00
bcoles
5a57ea131e
resolve_sid: Add docs and resolve RuboCop violations
2023-04-23 17:39:32 +10:00
space-r7
9e1be62f06
Land #17462 , add WhatsUp Gold credential extractor
2023-03-17 16:44:17 -05:00
space-r7
eec73fe394
add module changes
2023-02-23 16:34:43 -06:00
adfoster-r7
6870efc34a
Land #17426 , Update all references to old Wiki to point to new docs site
2023-02-01 23:49:20 +00:00
Jack Heysel
c90a6f9068
Land #17406 , veeam_credential_dump post module
...
Veeam Backup & Recovery and Veeam ONE Monitor credential
capture post module for versions 9.x and 11.x.
2023-02-01 17:29:05 -05:00
Grant Willcox
6043d0ffba
Update all links from Wiki site to new docs site.
2023-01-27 09:58:53 -06:00
npm-cesium137-io
8ed4f59c60
veeam_credential_dump refinement
...
Fixed stupid typo in markdown.
Fixed a bug in the export code that prevented the disposition column
from being exported.
2023-01-18 14:27:28 -05:00
npm-cesium137-io
243c57c1fe
Add whatsupgold_credential_dump post module
...
Add a post module for credential extraction from WhatsUp Gold instances
on Windows hosts. The module should theoretically decrypt ciphertext
from any version of WhatsUp Gold, although it has only been verified
working on WhatsUp Gold versions 11.0 through 22.0.
2023-01-10 15:50:53 -05:00
npm-cesium137-io
499d1ccfd7
Refactor veeam_credential_dump
...
Changed the SQL queries for DB dump to explicit VARCHAR(4096) to get
around sqlcmd's 256-char column limit.
Refactored the BATCH_DPAPI functionality because I can't seem to let
this pattern go: now actually batches with byte threshold set by
advanced option.
Reduced clutter and redundancy.
Various tweaks and bug fixes.
Updated documentation.
2023-01-09 16:31:44 -05:00
npm-cesium137-io
9cc8d41388
veeam_credential_dump post module revisions
...
Cleanup for initial PR.
2022-12-21 15:53:46 -05:00
Christophe De La Fuente
6758c8313f
Land #17258 , Update sharphound
2022-12-21 14:04:09 +01:00
Christophe De La Fuente
fa5e4df3f5
Land #17278 , Add solarwinds_orion_dump post module
2022-12-20 15:42:25 +01:00
npm-cesium137-io
e3c6aa7820
solarwinds_orion_dump attribution update
...
Updated original research attribution to align with reality.
2022-12-20 08:55:19 -05:00
npm-cesium137-io
d04111ad6f
solarwinds_orion_dump markdown update
...
Nuked the last embarrassing typo in the module description.
Updated the documentation to include detail on sqlcmd / CSV export
process when manually exporting the data.
2022-12-12 10:54:41 -05:00
npm-cesium137-io
6eaa0bfab2
Add veeam_credential_dump post module
...
Post module for Veeam Backup and Replication / Veeam ONE Monitor Server
credential extract
2022-12-10 16:21:59 -05:00
npm-cesium137-io
8075654f10
Revise solarwinds_orion_dump MKII
...
Fixed humiliating typos in the markdown doc.
Updated the Author section of the module per guidelines.
Changed credential type for AES key loot storage.
Updated database config code to include the case where the SQL password
is not encrypted (needs testing).
Additional tweaks and fixes.
2022-12-09 14:47:18 -05:00
npm-cesium137-io
2f3fd6c917
Revise solarwinds_orion_dump
...
Made modifications to documentation to add further detail for each
action.
Significant refactor of error handling, now with (hopefully) proper use
of exceptions.
Various suggested code improvements and optimization.
Fixed some redundant and buggy code.
2022-12-07 07:55:43 -05:00
bcoles
d90dee8235
enum_proxy: Cleanup and support non-Meterpreter sessions
2022-12-04 15:10:47 +11:00
Jeffrey Martin
453cfc5939
spelling change per review
...
Co-authored-by: adfoster-r7 <60357436+adfoster-r7@users.noreply.github.com >
2022-11-23 13:26:19 -06:00
Jeffrey Martin
cb8e023734
add warning about external links
...
Links to external resources not controlled by the project maintainers
are subject to bitrot and malicious take over. Warnings seem appropriate.
2022-11-23 12:08:05 -06:00
npm-cesium137-io
6f885ba700
Add solarwinds_orion_dump post module
...
Post module for extracting encrypted credentials from SolarWinds Orion
NPM. Tested on the 2020 version.
2022-11-18 10:40:10 -05:00
h00die
496a6f74ff
remove verbiage of list
2022-11-17 16:49:11 -05:00
h00die
f6eba6a836
updated bloodhound module
2022-11-13 14:29:28 -05:00
Christophe De La Fuente
929d4f2fa4
Land #17097 , Gather Navicat
2022-11-07 12:30:16 +01:00
bwatters
4aa2b76bde
Land #17092 , netlm_downgrade Cleanup and support non-Meterpreter sessions
...
Merge branch 'land-17092' into upstream-master
2022-10-12 11:40:20 -05:00
三米前有蕉皮
20015d7351
Update documentation/modules/post/windows/gather/credentials/navicat.md
...
Co-authored-by: Christophe De La Fuente <56716719+cdelafuente-r7@users.noreply.github.com >
2022-10-12 13:52:12 +08:00
三米前有蕉皮
7caf2eb9dc
Update documentation/modules/post/windows/gather/credentials/navicat.md
...
Co-authored-by: Christophe De La Fuente <56716719+cdelafuente-r7@users.noreply.github.com >
2022-10-12 11:29:25 +08:00
Jack Heysel
60c21da50e
Land #17009 , Add MobaXterm cred gather module
...
This module determines if MobaXterm is installed and if
it is dumps all saved session information from the target
2022-10-05 14:14:27 -04:00
bwatters
052d233bd9
Land #17006 , Gather_RedisDesktopManager_Password
...
Merge branch 'land-17006' into upstream-master
2022-10-03 15:10:30 -05:00
cn-kali-team
3fa2268aa1
fix username
2022-10-03 00:07:30 +08:00
cn-kali-team
2f3378fc4a
Gather_Navicat
2022-10-02 23:48:09 +08:00
bcoles
3ffbc99d9f
netlm_downgrade: Cleanup and support non-Meterpreter sessions
2022-10-01 22:35:11 +10:00
Jack Heysel
9ad513dade
Land #16933 , Thycotic Secret Server post module
...
This PR adds a post exploitation module that exports
and decrypts Thycotic Secret Server credentials
2022-09-30 13:16:05 -04:00
bwatters
9e74b9887d
Land #17048 , enum_tokens: Cleanup
...
Merge branch 'land-17048' into upstream-master
2022-09-29 15:58:46 -05:00
jheysel-r7
e06acc7df0
Update documentation/modules/post/windows/gather/credentials/thycotic_secretserver_dump.md
2022-09-29 13:59:01 -04:00
jheysel-r7
e8d4bcdcc6
Update documentation/modules/post/windows/gather/credentials/thycotic_secretserver_dump.md
2022-09-29 13:58:37 -04:00
jheysel-r7
713d63654b
Update documentation/modules/post/windows/gather/credentials/thycotic_secretserver_dump.md
2022-09-29 13:58:22 -04:00