aboutsummaryrefslogtreecommitdiff
path: root/Exfiltration/Exfiltration.psd1
AgeCommit message (Collapse)AuthorFilesLines
2015-12-18Set all module versions to 3.0Matt Graeber1-16/+1
Also cleaned up some module manifest cruft.
2014-06-30Get-VaultCredential now takes the singular form.mattifestation1-2/+2
2014-05-30Issue #43 - Adding Get-VaultCredentialsmattifestation1-41/+2
Displays Windows vault credential objects including cleartext web credentials.
2014-03-01Added Get-VolumeShadowCopy and Mount-VolumeShadowCopymattifestation1-1/+2
2014-02-12Merge pull request #28 from clymb3r/masterMatt Graeber1-1/+1
Inject-LogonCredentials has been renamed to Invoke-CredentialInjection.
2014-02-12Inject-LogonCredentials has been renamed to Invoke-CredentialInjection.clymb3r1-1/+1
Added a check to ensure the script isn't being run from Session0 with the "NewWinLogon" flag. This flag does not work in Session0 because winlogon.exe tries to load stuff from user32.dll which requires a desktop is present. This is not possible in Session0 because there is no desktop/GUI, so it causes winlogon to load and then immediately close with error code c0000142 indicating a DLL failed to initialize. There is no way to fix this that I know of, if you need to run the script from Session0 use the "ExistingWinLogon" flag.
2013-11-18Merge pull request #21 from clymb3r/masterMatt Graeber1-1/+1
Adding Inject-LogonCredentials
2013-11-17Adding Inject-LogonCredentialsclymb3r1-1/+1
2013-11-13Normalized all scripts to ASCII encodingmattifestation1-2/+2
2013-11-03Adding Invoke-TokenManipulationclymb3r1-1/+1
2013-10-01Adding Invoke-Mimikatz and Invoke-Ninjacopyclymb3r1-1/+2
2013-07-03Updated Get-GPPPasswordMatt Graeber1-1/+1
2013-06-30Added Get-KeystrokesMatt Graeber1-1/+1
Get-Keystrokes is a PowerShell keylogger
2013-05-15Added Out-MinidumpMatt Graeber1-1/+2
Out-Minidump writes a process dump file with all process memory to disk. This is similar to running procdump.exe with the '-ma' switch.
2013-01-20Added 'Exfiltration' Modulebitform1-0/+87