aboutsummaryrefslogtreecommitdiff
path: root/Exfiltration/mimikatz-1.0/driver/notify_reg.h
diff options
context:
space:
mode:
authormattifestation <mattgraeber@gmail.com>2014-02-03 17:13:35 -0500
committermattifestation <mattgraeber@gmail.com>2014-02-03 17:13:41 -0500
commitc5168cdba6a3b2d7dd8d79c8ac9583d3ace6a504 (patch)
tree31e4238db4984481442faa780e8921782c5de848 /Exfiltration/mimikatz-1.0/driver/notify_reg.h
parentd9ca5357e4603222268b1c619da10cc7858153d4 (diff)
downloadPowerSploit-c5168cdba6a3b2d7dd8d79c8ac9583d3ace6a504.tar.gz
PowerSploit-c5168cdba6a3b2d7dd8d79c8ac9583d3ace6a504.zip
Removed mimikatz.
This doesn't need to reside in PowerSploit. Those that are truly paranoid should validate that the embedded executable in Invoke-Mimikatz.ps1 is indeed mimikatz. This was causing AV to flag upon downloading PowerSploit.
Diffstat (limited to 'Exfiltration/mimikatz-1.0/driver/notify_reg.h')
-rw-r--r--Exfiltration/mimikatz-1.0/driver/notify_reg.h17
1 files changed, 0 insertions, 17 deletions
diff --git a/Exfiltration/mimikatz-1.0/driver/notify_reg.h b/Exfiltration/mimikatz-1.0/driver/notify_reg.h
deleted file mode 100644
index ce86568..0000000
--- a/Exfiltration/mimikatz-1.0/driver/notify_reg.h
+++ /dev/null
@@ -1,17 +0,0 @@
-#pragma once
-#include "notify.h"
-
-ULONG * CmpCallBackCount;
-PVOID * CmpCallBackVector;
-PLIST_ENTRY CallbackListHead;
-
-typedef struct _KIWI_REGISTRY6_CALLBACK
-{
- LARGE_INTEGER cookie;
- PVOID context;
- PVOID callback;
- UNICODE_STRING altitude;
-} KIWI_REGISTRY6_CALLBACK, *PKIWI_REGISTRY6_CALLBACK;
-
-NTSTATUS getNotifyRegistryRoutine();
-NTSTATUS kListNotifyRegistry(LPWSTR pszDest, size_t cbDest, LPWSTR *ppszDestEnd, size_t *pcbRemaining);