Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Post/aux modules for Recall collection #19250

Open
sempervictus opened this issue Jun 8, 2024 · 3 comments
Open

Post/aux modules for Recall collection #19250

sempervictus opened this issue Jun 8, 2024 · 3 comments
Labels
suggestion-feature New feature suggestions

Comments

@sempervictus
Copy link
Contributor

Summary

We probably want to include collection, parsing, and analysis of Recall data la this netexec PR or the totalrecall script.

Basic example

  1. Connect over RPC to remote windows machine/get a session (post version)
  2. Enumerate/qualify Recall state and storage locations
  3. Collect contents of storage and relevant registry/database info for access
  4. Parse and extract recall data
  5. Report notes, creds, and other useful information while storing parsed loot and (optionally) entire collected sample

Motivation

Because
image

@sempervictus sempervictus added the suggestion-feature New feature suggestions label Jun 8, 2024
@Marshall-Hallenbeck
Copy link

Looks like @xaitax already pretty much did that? https://x.com/xaitax/status/1799140614241501550

@xaitax
Copy link
Contributor

xaitax commented Jun 8, 2024

I will check what's required in terms of changes or if feasible at all on the 18th. 👍🏻 No point adding it now anymore.

@adfoster-r7
Copy link
Contributor

This sounds cool; Is it a useful module still with the recent news? 👀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
suggestion-feature New feature suggestions
Projects
None yet
Development

No branches or pull requests

4 participants