user avatar
SkelSec
@SkelSec
CEO and Co-Founder of Octopwn
Joined June 2014
Posts
  • user avatar
    I waited 2 years for this, rewrote impacket for this, asked cryptographers to remake algos in python for this, spent enormous time of my life to make this happen. and it's finally here this finally works and I can't find the words to express my satisfaction.
  • user avatar
  • user avatar
  • user avatar
    Replying to @SkelSec
    For those who might not see what this is: Fully working SMB protocol implementation is webassembly, it runs in your browser
  • user avatar
    New article on bypassing AV via duplicating foreign process handles using #pypykatz #xdr #Endpoints #infosec #BlueTeam #redteam
  • user avatar
    Kerberoasting just got a bit more entertaining. Yes, it is happening live on a domain controller. Cool things coming up :) -wish I had a gaming dev team- #VR #hacking #infosec
    00:00
  • user avatar
    Wrote an article on defeting "anti mimikatz" protection mechanism in @PaloAltoNtwks Cortex XDR to get those sweet credentials out of LSASS dumps via #pypykatz. link.medium.com/qU9rAMmEcbb #xdr #Endpoints #infosec #BlueTeam #redteam
  • user avatar
    Releasing a new project: pypykatz-server With this you won't need to run #mimikatz/#pypykatz on the target machine, only a tiny agent (13kB) that takes the info from the server on what parts of the lsass process to read. github.com/skelsec/pypyka… github.com/skelsec/pypyka…
  • user avatar
    pypykatz 0.3.0 is out. Now parsing dumps that #mimikatz can't parse :) New features: 1. better template selection. 2. greppable output 3. made place for upcoming NT support 4. supports external readers, like @HackAndDo 's upcoming #impacket interface
  • user avatar
    New #pypykatz verison (0.4.8) is out on pip and github. new features: remote LSASS file dump+ parse (SMB) remote registry dump+parse (SMB) dcsync (SMB/RPC) 'secretsdump' added reduced parsing time (by over 20%) option to specify target packages to parse
  • user avatar
    This took a while... New #pypykatz release (0.5.1) avilable on pip/github/win/linux/firefox/chrome par/printnightmare (@cube0x0) rdp creds (live and offline) (thx @gentilkiwi) credman credentials without touching lsass (thx @tiraniddo) and other stuff
  • user avatar
    Managed to create the exploit for @tiraniddo 's latest Kerberos findings! #feelsaccomplished
  • user avatar
  • user avatar