Join GitHub today
GitHub is home to over 28 million developers working together to host and review code, manage projects, and build software together.Sign up
Added Invoke-PasswordFilterImplant powershell module #1183
Added the Invoke-PasswordFilterImplant module. This module drops a custom password filter DLL that allows the capture of a user's credentials. Each password change event on a domain will trigger the registered DLL in order to exfiltrate the username and new password value prior successfully changing it in the Active Directory (AD).
Here is the link to the DLL in the code: https://github.com/GoSecure/DLLPasswordFilterImplant