Processus
Processus
Hekatomb is a python script that connects to LDAP directory to retrieve all computers and users informations. Then it will download all DPAPI blob of all users from all computers...
When I try to use the Powershell script to load a vulnerable dll, the compressed file seems to be corrupted when the script uncompress it. Tried on fresh Server 2022...
see : 
Adding defense evasion technique with dictionnary association obfuscation
Hello :) I made an extension for the Havoc framework that uses GitHub issues to communicate between the teamserver and the agent. Here is the GitHub project : https://github.com/ProcessusT/HavocHub And...