
SAMDump
Extract the SAM and SYSTEM hives using the Volume Shadow Copy (VSS) API. With exfiltration and XOR obfuscation options. Implemented in C#, C++,…

Extract the SAM and SYSTEM hives using the Volume Shadow Copy (VSS) API. With exfiltration and XOR obfuscation options. Implemented in C#, C++,…

Async BOF to automatically extract or renew Kerberos TGTs on a target system.

BOF-based tool to extract browser cookies and credentials from Chrome, Edge, and Firefox via handle duplication and fileless download, with offline…

Tool to remotely dump secrets from the Windows registry

Post-Exploitation EVTX Analyzer for BloodHound Mapping

gpoParser is a tool designed to extract and analyze configurations applied through Group Policy Objects (GPOs) in an Active Directory environment.

Extract Windows credentials directly from VM memory snapshots and virtual disks

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…

Dump LSASS via physical memory read primitives in vulnerable kernel drivers

A system administration or post-exploitation script to automatically extract the bitlocker recovery keys from a domain.

Extract registry and NTDS secrets from local or remote disk images

A python tool to automate KeePass discovery and secret extraction.

SessionGopher is a PowerShell tool that uses WMI to extract saved session information for remote access tools such as WinSCP, PuTTY, SuperPuTTY,…

Aggrokatz is an aggressor plugin extension for Cobalt Strike which enables pypykatz to interface with the beacons remotely and allows it to parse…

Extract stored credentials from Internet Explorer and Edge

Extracting Clear Text Passwords from mstsc.exe using API Hooking.

Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS