adfoster-r7
afbf9af930
Merge pull request #19600 from adfoster-r7/mark-enum-chrome-as-superseded
...
Mark older browser modules for windows as superceded
2024-10-31 11:33:03 +00:00
adfoster-r7
5e217fb93a
Mark enum_chrome as superceded
2024-10-30 16:21:05 +00:00
adfoster-r7
7b745b2dcb
Merge pull request #19506 from xaitax/enum_browsers
...
Add Browser Data Extraction for Chromium- and Gecko-based Browsers
2024-10-30 15:30:56 +00:00
Alex
6fb49a27e0
[Added] Improvements after review
2024-10-24 13:48:50 +02:00
adfoster-r7
88825a022c
Remove trailing whitespace
2024-10-23 23:41:20 +01:00
Alex
1fa9c6a774
[Fixed] Opera Support
2024-10-21 17:03:37 +02:00
Alex
e6aa695e99
Update enum_browsers.rb
2024-10-21 09:48:24 +02:00
Alex
ecd9f99d16
[Added] Extract Browser Cache
2024-10-20 23:15:18 +02:00
Alex
a2d8d7dd76
[Added] Extract Installed Browser Extensions (Name & Version)
2024-10-20 21:23:06 +02:00
Alex
6d272759dc
Add Browser Version Detection and display System Information
2024-10-11 12:13:48 +02:00
Alex
91beef1dbb
Add BROWSER_TYPE option to choose between Chromium, Gecko, or both for data extraction
2024-10-10 20:08:14 +02:00
Alex
47c4679d6b
Fixed migration logic
2024-10-10 19:28:03 +02:00
Alex
d3ae5a9ab0
Abort when session is running under SYSTEM privileges.
2024-10-10 13:25:11 +02:00
Alex
cd487715c4
[Added] Migration to explorer.exe for user-context based extraction
2024-10-10 12:32:19 +02:00
GhostlyBox
967f7c30a0
Update enum_unattend.rb
...
Included checks for '.vmimport' files which may have been created by the AWS EC2 VMIE service which will still contain cleartext credentials.
2024-10-07 17:58:30 +01:00
Alex
9eda0338af
Improved readability and other small fixes
2024-10-06 10:19:10 +02:00
Alex
6d28e4b350
Update modules/post/windows/gather/enum_browsers.rb
...
Co-authored-by: Valentin Lobstein <88535377+Chocapikk@users.noreply.github.com >
2024-09-27 08:03:02 +02:00
Alex
4a9754313a
Update modules/post/windows/gather/enum_browsers.rb
...
Co-authored-by: Valentin Lobstein <88535377+Chocapikk@users.noreply.github.com >
2024-09-27 08:02:57 +02:00
Alex
1e67d200d2
Update modules/post/windows/gather/enum_browsers.rb
...
Co-authored-by: Valentin Lobstein <88535377+Chocapikk@users.noreply.github.com >
2024-09-27 08:02:48 +02:00
Alex
78f7327ea7
Update enum_browsers.rb
2024-09-26 20:49:42 +02:00
Alex
6cc6841821
Update modules/post/windows/gather/enum_browsers.rb
...
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com >
2024-09-26 20:44:45 +02:00
Alex
f106f1cf2c
Add enum_browsers post exploitation module
...
This post-exploitation module extracts sensitive browser data from both Chromium-based and Gecko-based browsers on the target system. It supports the decryption of passwords and cookies using Windows Data Protection API (DPAPI) and can extract additional data such as browsing history, keyword search history, download history, autofill data, and credit card information.
2024-09-26 19:21:42 +02:00
adfoster-r7
62a3f73e70
Update rubocop target ruby version
2024-07-24 16:47:17 +01:00
bwatters
f8c69e434d
Land #19173 , Add CarotDAV FTP PackRat module
...
Merge branch 'land-19173' into upstream-master
2024-05-17 16:49:33 -05:00
bwatters
8a68eebbf6
Land #19171 , Add Sylpheed Email PackRat module
...
Merge branch 'land-19171' into upstream-master
2024-05-17 10:39:56 -05:00
Jacob
175e16a29a
Removed unused regex search
...
Co-authored-by: cgranleese-r7 <69522014+cgranleese-r7@users.noreply.github.com >
2024-05-17 09:59:20 -05:00
Jacob
a8f1d35773
Re-structured artifact enumeration option
...
Co-authored-by: cgranleese-r7 <69522014+cgranleese-r7@users.noreply.github.com >
2024-05-17 09:59:20 -05:00
-Pink-Panther
39630f1d2b
Added post module for Adi IRC Client
2024-05-17 09:58:23 -05:00
Jacob
6de0048354
Removed unused regex search
...
Co-authored-by: cgranleese-r7 <69522014+cgranleese-r7@users.noreply.github.com >
2024-05-16 19:15:00 -05:00
-Pink-Panther
d08247776c
Re-arranged Author list
2024-05-16 19:12:54 -05:00
-Pink-Panther
cf15b1f858
Added post module for Quassel IRC Client
2024-05-16 19:12:54 -05:00
Jacob
7a33970ef8
Re-structured artifact enumeration option
...
Co-authored-by: cgranleese-r7 <69522014+cgranleese-r7@users.noreply.github.com >
2024-05-15 14:58:51 +01:00
Jacob
554c5c3cb4
Re-structured artifact enumeration option
...
Co-authored-by: cgranleese-r7 <69522014+cgranleese-r7@users.noreply.github.com >
2024-05-15 14:52:58 +01:00
Jacob
121d3ded85
Re-structured artifact enumeration option
...
Co-authored-by: cgranleese-r7 <69522014+cgranleese-r7@users.noreply.github.com >
2024-05-15 14:07:48 +01:00
Jacob
8259db4756
Removed unused regex search
...
Co-authored-by: cgranleese-r7 <69522014+cgranleese-r7@users.noreply.github.com >
2024-05-15 14:06:58 +01:00
-Pink-Panther
1326849076
Added post module & documentation for CarotDAV FTP Client
2024-05-08 10:54:33 -04:00
-Pink-Panther
c5500a3337
Added post module & documentation for Sylpheed email Client
2024-05-08 10:09:49 -04:00
-Pink-Panther
b3f2904e75
Re-arranged Author list
2024-05-07 16:22:51 -04:00
-Pink-Panther
37c068a66e
RuboCop Fixes
2024-05-07 13:25:52 -04:00
-Pink-Panther
ee2ca6a35b
Added post module for Halloy IRC Client
2024-05-07 12:51:25 -04:00
Patrick Double
8b1ff6d44e
change bloodhound OutputDirectory to OptString
...
OptPath is intended for a local path and performs validation. Attempting to set it to a target path that doesn't exist on the local fails.
2024-02-29 07:12:37 -06:00
adfoster-r7
5fa1ce8ed2
Add support for newer sqlcmd versions
2024-02-12 11:51:02 +00:00
adfoster-r7
48221e594d
Land #18704 , Leverage the module metadata cache in the module_sets
2024-02-02 14:16:46 +00:00
Dean Welch
2cf045d3c4
Leverage the module metadata cache in the module_sets
2024-01-15 14:56:46 +00:00
bwatters
57c882cab5
Land #18604 , Add Post Windows Gather to perform Mikrotik Winbox "Keep Password" credentials extraction
...
Merge branch 'land-18604' into upstream-master
2024-01-09 15:38:35 -06:00
siddolo
dc6d84d823
Update modules/post/windows/gather/credentials/winbox_settings.rb
...
Co-authored-by: Brendan <bwatters@rapid7.com >
2024-01-09 00:43:10 +01:00
bwatters
a0bc08c6ec
Quick change to add support for more sessions and to only read the file once
2024-01-05 17:33:54 -06:00
Jack Heysel
3bad98afc6
Land #18488 , add kerberos_tickets post module
...
Adds a module to manage kerberos tickets from a compromised
host. This PR also includes rail gun enhancements.
2023-12-07 19:12:48 -05:00
siddolo
48e2e09dfc
msftidy fix
2023-12-07 19:23:33 +01:00
siddolo
05800296f3
RuboCop fixes and msftidy fixes
2023-12-07 13:45:19 +01:00