Navigation Menu

Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Import credentials and hashes from kiwi/mimikatz into the creds store #14276

Closed
Viss opened this issue Oct 16, 2020 · 1 comment · Fixed by #14432
Closed

Import credentials and hashes from kiwi/mimikatz into the creds store #14276

Viss opened this issue Oct 16, 2020 · 1 comment · Fixed by #14432
Labels
suggestion-feature New feature suggestions

Comments

@Viss
Copy link

Viss commented Oct 16, 2020

It seems like the creds that land in the credential store come out of various modules like smb_login and other bruteforce-type modules, but the credentials that tend to be the most juicy are the ones we can get out of kiwi/mimikatz, and it would be super helpful if msf would record those, otherwise its the "hold page up for a while and hope you still have them in backscroll" game.

@Viss Viss added the suggestion-feature New feature suggestions label Oct 16, 2020
@jmartin-tech
Copy link
Contributor

Consider using post/windows/gather/credentials/sso. This module will use kiwi on a meterpreter session to gather and store details.

msf6 > search Mimikatz

Matching Modules
================

   #  Name                                                 Disclosure Date  Rank    Check  Description
   -  ----                                                 ---------------  ----    -----  -----------
   0  auxiliary/admin/kerberos/ms14_068_kerberos_checksum  2014-11-18       normal  No     MS14-068 Microsoft Kerberos Checksum Validation Vulnerability
   1  post/windows/escalate/golden_ticket                                   normal  No     Windows Escalate Golden Ticket
   2  post/windows/gather/credentials/sso                                   normal  No     Windows Single Sign On Credential Collector (Mimikatz)
   3  post/windows/manage/wdigest_caching                                   normal  No     Windows Post Manage WDigest Credential Caching

Detection of credentials from interactive meterpreter session responses sounds interesting, the existing post module may work as an interim option.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
suggestion-feature New feature suggestions
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants