diff --git a/Offensive.md b/Offensive.md index bb0120a..6ec41a3 100644 --- a/Offensive.md +++ b/Offensive.md @@ -1016,6 +1016,10 @@ Some tools can be categorized in more than one category. But because the current peewpw/Invoke-WCMDump PowerShell Script to Dump Windows Credentials from the Credential Manager + + Pickfordmatt/SharpLocker + SharpLocker helps get current user credentials by popping a fake Windows lock screen, all output is sent to Console which works perfect for Cobalt Strike. + PorLaCola25/TransactedSharpMiniDump Implementation of b4rtiks's SharpMiniDump using NTFS transactions to avoid writting the minidump to disk and exfiltrating it via HTTPS using sockets.