

Extract registry and NTDS secrets from local or remote disk images

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…

gpoParser is a tool designed to extract and analyze configurations applied through Group Policy Objects (GPOs) in an Active Directory environment.

SessionGopher is a PowerShell tool that uses WMI to extract saved session information for remote access tools such as WinSCP, PuTTY, SuperPuTTY,…

tool to extract passwords from TeamViewer memory using Frida

Post-Exploitation EVTX Analyzer for BloodHound Mapping

Dump LSASS via physical memory read primitives in vulnerable kernel drivers

Async BOF to automatically extract or renew Kerberos TGTs on a target system.

Extract Windows credentials directly from VM memory snapshots and virtual disks

Extract the SAM and SYSTEM hives using the Volume Shadow Copy (VSS) API. With exfiltration and XOR obfuscation options. Implemented in C#, C++,…

Extracting Clear Text Passwords from mstsc.exe using API Hooking.

Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS

Extract stored credentials from Internet Explorer and Edge

Tool to remotely dump secrets from the Windows registry

Aggrokatz is an aggressor plugin extension for Cobalt Strike which enables pypykatz to interface with the beacons remotely and allows it to parse…

A system administration or post-exploitation script to automatically extract the bitlocker recovery keys from a domain.