
Chrome-App-Bound-Encryption-Decryption
Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…

Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS

Extract Windows credentials directly from VM memory snapshots and virtual disks

Extracting Clear Text Passwords from mstsc.exe using API Hooking.

SessionGopher is a PowerShell tool that uses WMI to extract saved session information for remote access tools such as WinSCP, PuTTY, SuperPuTTY,…

BOF-based tool to extract browser cookies and credentials from Chrome, Edge, and Firefox via handle duplication and fileless download, with offline…

Tool to remotely dump secrets from the Windows registry

A python tool to automate KeePass discovery and secret extraction.

tool to extract passwords from TeamViewer memory using Frida

A system administration or post-exploitation script to automatically extract the bitlocker recovery keys from a domain.

Extract the SAM and SYSTEM hives using the Volume Shadow Copy (VSS) API. With exfiltration and XOR obfuscation options. Implemented in C#, C++,…

gpoParser is a tool designed to extract and analyze configurations applied through Group Policy Objects (GPOs) in an Active Directory environment.

Dump LSASS via physical memory read primitives in vulnerable kernel drivers

Extract stored credentials from Internet Explorer and Edge

Aggrokatz is an aggressor plugin extension for Cobalt Strike which enables pypykatz to interface with the beacons remotely and allows it to parse…

Async BOF to automatically extract or renew Kerberos TGTs on a target system.