Skip to content

ufrisk/MemProcFS-plugins

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

29 Commits
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Plugins for MemProcFS

This repository contains various non-core plugins for MemProcFS - The Memory Process File System.

Plugins range from non-core plugins to plugins that have offensive capabilities - such as pypykatz. Please find a short description for each plugin below:

pypykatz

Author:

Tamas Jos (@skelsec) , [email protected] , https://github.com/skelsec/

Overview:

pypykatz for MemProcFS exposes mimikatz functionality in the folder /py/secrets/ in the file system root provided that the target is a supported Windows system. Functionality includes retrieval of hashes, passwords, kerberos tickets and various other credentials.

Installation instructions:

  1. Ensure MemProcFS supported version of 64-bit Python for Windows is on the system path (or specify in -pythonpath option when starting MemProcFS). NB! embedded Python will not work with pypykatz since it requires access to Python pip installed packages.
  2. Install pypykatz pip package, in correct python environment, by running pip install dissect.cstruct pypykatz.
  3. Copy the pypykatz for MemProcFS plugin by copying all files from /files/plugins/pym_pypykatz to corresponding folder in MemProcFS - overwriting any existing files there.
  4. Start MemProcFS.

Last updated: 2021-03-21

pypykatz regsecrets

Author:

Tamas Jos (@skelsec) , [email protected] , https://github.com/skelsec/

Overview:

regsecrets for MemProcFS exposes mimikatz functionality in the folder /py/regsecrets/ in the file system root provided that the target is a supported Windows system. Functionality includes retrieval NTLM hashes for local accounts amongst other things.

Installation instructions:

  1. Ensure MemProcFS supported version of 64-bit Python for Windows is on the system path (or specify in -pythonpath option when starting MemProcFS). NB! embedded Python will not work with pypykatz and aiowinreg since it requires access to Python pip installed packages.
  2. Install pypykatz and aiowinreg pip package, in correct python environment, by running pip install pypykatz aiowinreg.
  3. Copy the pyregsecrets for MemProcFS plugin by copying all files from /files/plugins/pym_regsecrets to corresponding folder in MemProcFS - overwriting any existing files there.
  4. Start MemProcFS.

Last updated: 2021-03-21

About

No description, website, or topics provided.

Resources

License

Stars

Watchers

Forks

Packages

No packages published

Languages