Commit Graph

135 Commits

Author SHA1 Message Date
Matt Graeber 65cd074eaf Merge pull request #13 from clymb3r/master
Call to DllMain when unloading reflective DLL
2013-09-04 04:54:15 -07:00
clymb3r 5e1f6ac29a Call to DllMain when unloading reflective DLL
Prior to this fix, DllMain with the ProessDetach flag was not called
when unloading the reflectively loaded DLL. This was causing very weird
crashes in the Invoke-NinjaCopy script which is built on this script.
This should fix the crash.
2013-09-03 20:10:18 -07:00
mattifestation 6807da424f Added ProcessModuleTrace cmdlets
Added *-ProcessModuleTrace cmdlets to trace details when modules are
loaded into a process. These can be useful for malware analysis.
2013-08-29 19:56:01 +00:00
Matt Graeber fcdd3ad642 Explicitly casting types as [Type]
The latest version of .NET added generics to many of the InteropService
methods. Therefore, all of my uses of types need to be explicitly cast
with [Type].
v2.2
2013-08-17 17:55:31 -04:00
Matt Graeber 7f0be861f2 Added ps1xml file for Get-ILDisassembly
Output from Get-ILDisassembly is slightly cleaner.
2013-08-17 17:39:04 -04:00
Matt Graeber 9bb31fc9b9 Removing Get-PEArchitecture
This functionality is present and maintained in Get-PEHeader.
2013-08-17 17:16:38 -04:00
Matt Graeber 05d335512a Get-Keystrokes now accepts relative paths 2013-08-17 16:56:11 -04:00
Matt Graeber d67e71bf2d Out-Minidump now provides descriptive output
Out-Minidump now outputs a FileInfo object (i.e. the same output as
Get-ChildItem) upon successfully creating a dump file.
2013-08-17 16:39:20 -04:00
Matt Graeber ba33613413 Added additional error handling to Get-GPPPassword 2013-08-17 16:31:48 -04:00
Matt Graeber 66face4488 Merge pull request #11 from hajdbo/patch-1
added ErrorAction SilentlyContinue to Get-ChildItem
2013-08-17 17:04:15 -07:00
Matt Graeber 9577a4e2c2 Compiler parameters were not applied to Add-Type
The compiler parameters were not being applied to Add-Type in
Get-PEHeader. Derp.
This led to unexpected errors when Visual Studio environment variables
were defined.
2013-08-16 06:28:47 -04:00
hajdbo c623814116 added ErrorAction SilentlyContinue to Get-ChildItem
Sometimes you will have a denied access to a directory.
"ErrorAction SilentlyContinue" will continue searching recursively in \SYSVOL even when it encounters a directory where access is denied.
2013-08-12 12:04:38 +02:00
Matt Graeber 98be62a03a Get-PEHeader can now return raw section data 2013-07-28 16:04:07 -04:00
Matt Graeber 4eca7b0126 Latest version of .NET Framework broke Get-PEHeader
To fix this, I needed to explicitly cast types in the SizeOf and
PtrToStructure methods.
2013-07-28 14:32:40 -04:00
Matt Graeber 05c5832458 Latest version of .NET Framework broke Get-PEB
To fix this, I needed to explicitly cast types in the SizeOf and
PtrToStructure methods.
2013-07-11 18:20:05 -04:00
Matt Graeber 55a6dbd019 Added Get-ObjDump
Get-ObjDump parses and return information about one or more Windows
object files. It is similar to dumpbin but it returns objects!
2013-07-09 20:17:01 -04:00
Matt Graeber 030fc3b43b Merge pull request #10 from mattifestation/webstersprodigy-Portscan
Webstersprodigy portscan
2013-07-06 10:41:52 -07:00
Matt Graeber b507290d78 Added Invoke-Portscan to README 2013-07-06 13:38:35 -04:00
Matt Graeber 49b9523c10 Merge branch 'Portscan' of https://github.com/webstersprodigy/PowerSploit into webstersprodigy-Portscan
Conflicts:
	Recon/Recon.psd1
2013-07-06 13:34:12 -04:00
Matt Graeber 298561f26b Forgot to add CodeIntegrityInformation to help 2013-07-04 14:59:24 -04:00
Matt Graeber 2a45cfbd1e Get-NtSystemInformation can now query UMCI info
Get-NtSystemInformation now returns SystemCodeIntegrityInformation -
i.e. user-mode code integrity settings. This required reverse
engineering a dll that is only present on Windows 8 ARM devices.
2013-07-04 13:01:47 -04:00
Matt Graeber 9de59e9e3f Merge pull request #9 from obscuresec/master
Bug fix for error handling
2013-07-04 05:50:31 -07:00
Chris Campbell 2f28a29074 Update Get-TimedScreenshot.ps1
Fix error handling and various style problems
2013-07-03 22:15:05 -04:00
Chris Campbell 321e53ee23 Fix improper use of $Error[0] 2013-07-03 21:42:34 -04:00
Matt Graeber 29329e1707 Merge pull request #8 from obscuresec/master
Add checks to terminate script if not running in proper environment.
2013-07-03 17:44:35 -07:00
Chris Campbell eb85e1ce9d Terminating Errors Added
Added checks to ensure that the script is being ran on a domain-joined machine and with a domain account.
2013-07-03 20:31:53 -04:00
Matt Graeber 371c65c9a7 Updated Get-GPPPassword 2013-07-03 05:46:44 -04:00
Matt Graeber 717950d00c Added Get-Keystrokes
Get-Keystrokes is a PowerShell keylogger
2013-06-30 11:15:02 -04:00
Rich Lundeen 98510d8097 IPv6 support in hosts param 2013-06-25 22:07:36 -07:00
Rich Lundeen 05ab35a3af fixing EOL spaces (again, sorry) 2013-06-18 15:15:40 -07:00
Rich Lundeen 60a6044d36 fixing EOL spaces 2013-06-18 15:10:54 -07:00
Rich Lundeen 223527d4cd Addressed mattifestation feedback
See https://github.com/mattifestation/PowerSploit/pull/6#issuecomment-19289063

1) I like this feedback a lot and took it.

2) I tried going thread only but it got messed up with very large scans. Eventually,
I didn't think it was worth the amount of effort to make it reliable with only threads

3) Tried to do this

4) Did this

5) I like the idea in general and I took this one place (top-ports), but not for the two
examples you gave. The reasoning is, I want people to be able to specify various options
and arrays aren't that flexible. For example, I want people to specify a port list like
"80,90,8080-8090". Similar with CIDR, since that's one option, but they could also be
specifying hostnames e.g. "google.com,192.168.1.1/24,10.0.0.1"
2013-06-18 13:17:06 -07:00
Rich Lundeen af49f5cfaf small style update 2013-06-11 10:48:12 -07:00
Rich Lundeen 3ec7b95f8d Powershell 2.0 fixes - should work now 2013-06-11 10:22:37 -07:00
Rich Lundeen 03e0a0b489 fixing powershell 2.0 compat 2013-06-10 16:09:07 -07:00
Rich Lundeen 9a5b1ae75a removed a few comments 2013-06-09 21:18:38 -07:00
Rich Lundeen ebe7f0981a added invoke-portscan module 2013-06-09 21:08:44 -07:00
Matt Graeber 94751bc156 New-Object proxy function compatibility fix
I was calling the [Guid]::TryParse method that was only present in .NET
4 so this wasn't working in PowerShell v2.
2013-06-08 09:47:16 -04:00
Matt Graeber 12d1ebaac2 Forgot to add -Property param to CLSID option 2013-06-05 22:13:26 -04:00
Matt Graeber e210c89f39 Added New-Object proxy function
You can provide a CLSID (i.e. a Guid) to New-Object via the -ComObject
parameter in addition to a ProgId.
2013-06-05 22:03:27 -04:00
Matt Graeber 02c982dd18 Type names added to Get-NtSystemInformation
When displaying handle information, you can now filter by and display
object type names: Get-NtSystemInformation
2013-06-01 09:55:04 -04:00
Matt Graeber dfec277813 Added Invoke-ReflectivePEInjection
Another awesome addition from Joe Bialek. Invoke-ReflectivePEInjection
is a vast improvement over Invoke-ReflectiveDllInjection. It adds the
following features:

* Now supports loading exe files in memory
* Supports reflective dll injection into a remote process
* Additional sample Visual Studio solutions
2013-05-31 19:35:26 -04:00
Matt Graeber 6e5338c8a3 Fixed architecture detection bug in Get-PEB
I was checking processor architecture when I should have been checking
OS architecture.
2013-05-31 18:56:57 -04:00
Matt Graeber 9b4b3dcc73 Silly me. Just discovered the SetOffset method.
Thanks @JosephBialek!
2013-05-29 18:32:24 -04:00
Matt Graeber 7d5e884c3f ProcessParameters now displays properly 2013-05-25 08:58:24 -04:00
Matt Graeber 91bd44f0f0 Get-PEB now parses _RTL_USER_PROCESS_PARAMETERS 2013-05-24 21:16:43 -04:00
Matt Graeber 218f0cb24b "Best practice" improvements to Out-Minidump 2013-05-18 09:46:00 -04:00
Matt Graeber 3d27e6b7de _SYSTEM_HANDLE_INFORMATION prints as a table now 2013-05-16 20:40:21 -04:00
Matt Graeber c98734a764 Added _SYSTEM_LOCK_INFORMATION struct
Yet another method of leaking kernel pointers.
2013-05-16 20:21:04 -04:00
Matt Graeber af04f7e528 Added Out-Minidump
Out-Minidump writes a process dump file with all process memory to disk.
This is similar to running procdump.exe with the '-ma' switch.
2013-05-15 20:54:16 -04:00