Releases
v0.0.3
Compare
Sorry, something went wrong.
No results found
Commits
e7619df : Adjusted SCCM output (Duane Michael) #17
ffcfc12 : Added SCCM to machinetriage (Duane Michael) #17
67cc5f7 : Modified sccm output (Duane Michael) #17
1afc550 : Significantly cleaned up SCCM output. (Duane Michael) #17
0d1e17e : Add method to parse object data for sccm creds (guervild) #17
b7ff226 : changed nameof to true name (djhohnstein) #18
7485244 : Add HMAC validation to 3DES SHA1 (rxwx) #19
a81caa2 : Add support for specifying passwords in NTLM format (rxwx) #19
a88f7ac : Fixed bug in SID extraction. This should probably be moved to its own function that also tries to extract from the BK file (rxwx) #19
4ffd2bd : * Added option to dump masterkey hashes in john/hashcat format. (rxwx) #19
af40c84 : Update README.md (Rich Warren) #19
3322dbf : Fixed regex (guervild) #17
7ff2537 : support additional string types + code cleanup (Lee Christensen)
f75ab5a : Backupkey now not line wrapped (Will)
c811079 : Add Teams statekey support (Franci Šacer) #22
8cb5409 : adding user-context unprotect option for certificates (ptr0x1) #23
067535d : misc attributes properly pulled for some relevant cookie fields. updating to latest version of editthiscookie format. (Dwight Hohnstein) #25
578fe6e : Add /rpc flag to allow users to resquest domain controller to decrypt masterkeys in a domain (unknown) #27
dffd583 : Cleanup (Kiblyn11) #27
df4f883 : doc and cleanup (Kiblyn11) #27
b5af876 : Merge branch 'GhostPack:master' into master (c2biz)
a76e5e8 : Swapped Managed API usage for their CryptoServiceProvider alternatives to solve issues on systems with 'Use FIPS compliant algorithms for encryption, hashing, and signing' enabled. (Calvin Hedler) #29
4213573 : When running as local admin and getting the hashes of all masterkeys for all the users, the SID of the user now matches the right one (clod) #31
70ee50c : add ability to specify local state file (Lee Christensen) #32
d241fef : update docs (Lee Christensen) #32
4844a0f : added slack support to statekeys/cookies commands (Lee Christensen) #32
cda059a : update docs (Lee Christensen) #32
225a1fd : loosen access/sharing when trying to read files (Lee Christensen)
b348234 : Start of version 1.12.0 (Will) #34
8c9502a : Merge branch 'master' into pr/22 (Will) #22
f81707e : Merge branch 'pr/31' (Will) #31
670f215 : Merge branch 'master' into Version-1.12.0 (Will) #34
3dcfce2 : Added support for local prekey (Will) #35
1bc5902 : Update CHANGELOG (harmj0y)
709f9bc : Update README (Will)
049f35e : Update README.md (harmj0y)
a9649ad : Renamed prekey to credkey (Will)
1ee41c9 : Changed LSAAESDecrypt to use the AesManaged class instead of AesCryptoServiceProvider (Duane Michael) #37
10a0070 : Addressed FIPS issues by not enforcing FIPS policy in app.config (Duane Michael) #37
a095233 : Changed uses of the AesCryptoServiceProvider class to AesManaged in the sqllite crypto.cs (Duane Michael) #37
59fc248 : Changed uses of the (CryptoServiceProvider classes to *Managed in lib\Crypto.cs (Duane Michael) #37
8e805ce : Changed uses of the *CryptoServiceProvider class to *Managed in lib\Dpapi.cs (Duane Michael) #37
d1a048c : Changed uses of the *CryptoServiceProvider classes to *Managed in lib\Triage.cs (Duane Michael) #37
c81c6d1 : merge upstream/master (c2biz)
320980b : fix jq version syntax (c2biz)
8774022 : correct the path to jq.exe (c2biz)
You can’t perform that action at this time.