putterpanda / mimikittenz
- пятница, 8 июля 2016 г. в 03:13:40
PowerShell
A post-exploitation powershell tool for extracting juicy info from memory.
mimikittenz
is a post-exploitation powershell tool that utilizes the Windows function ReadProcessMemory()
in order to extract plain-text passwords from various target processes.
mimikittenz
can also easily extract other kinds of juicy info from target processes using regex patterns including but not limited to:
note: This tool is targeting running process memory address space, once a process is killed it's memory 'should' be cleaned up and inaccessible however there are some edge cases in which this does not happen.
The aim of mimikittenz
is to provide user-level (non-admin privileged) sensitive data extraction in order to maximise post exploitation efforts and increase value of information gathered per target.
Currently mimikittenz
is able to extract the following credentials from memory:
https://creativecommons.org/licenses/by/4.0/
[mimikittenz.MemProcInspector]::AddRegex("<NameOfTarget>","<regex_here>")
$matches=[mimikittenz.MemProcInspector]::InspectManyProcs("iexplore","chrome","firefox")
I'd love to see the list of regex's and target processe's grow in order to build a comprehensive post-exploitaiton hit list.