usbrubberducky-payloads/payloads/library/exfiltration/ntlm_exfiltration
Luu 0df3011601
Update README.md
2024-09-25 00:23:30 +02:00
..
README.md Update README.md 2024-09-25 00:23:30 +02:00
payload.txt Update payload.txt 2024-09-25 00:21:49 +02:00

README.md

Exfiltrate NTLM Hash - Windows

A script used to exfiltrate the NTLM hash on a Windows machine.

Description

A script used to capture and exfiltrate the NTLM hash of a Windows machine. It utilizes PowerShell to retrieve the SAM and SYSTEM files, then sends them to a Discord webhook. These files can than be used to extract the NTLM hash of all users.

Settings

  • Set the Discord webhook URL
  • Ensure the webhook permissions are configured

Credits

Luu176


Github