marcosd4h / Panda

Panda - is a set of utilities used to research how PsExec encrypts its traffic.

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Panda

Panda - is a set of utilities used to research how PsExec encrypts its traffic.

Shared library used to inject into lsass.exe process to log NTLM crypto functions.

kernel_panda.js is a WinDbg script used to log kernel smb crypto routines.

Full writeup(rus) available here: https://archercreat.github.io/psexec_encryption/

Disclamer

The CMakeLists file will not work on your system, sorry :p

About

Panda - is a set of utilities used to research how PsExec encrypts its traffic.


Languages

Language:C++ 83.3%Language:JavaScript 12.0%Language:CMake 4.2%Language:C 0.4%