From 46baff5ef25ebdbdb7ac32f0c1f592dbd76e3245 Mon Sep 17 00:00:00 2001 From: mattifestation Date: Mon, 18 Nov 2013 06:30:19 -0500 Subject: Added Inject-LogonCredentials to README --- README.md | 4 ++++ 1 file changed, 4 insertions(+) (limited to 'README.md') diff --git a/README.md b/README.md index bc96a24..004d4af 100644 --- a/README.md +++ b/README.md @@ -148,6 +148,10 @@ Locates single Byte AV signatures utilizing the same method as DSplit from "clas Lists available logon tokens. Creates processes with other users logon tokens, and impersonates logon tokens in the current thread. +#### `Inject-LogonCredentials` + +Create logons with clear-text credentials without triggering a suspicious Event ID 4648 (Explicit Credential Logon). + #### `Invoke-NinjaCopy` Copies a file from an NTFS partitioned volume by reading the raw volume and parsing the NTFS structures. -- cgit v1.2.3