Initial public version

This commit is contained in:
Michael Grafnetter
2026-07-21 13:18:25 +02:00
parent 1b7bc180ce
commit 3ff16fab05
11 changed files with 27 additions and 15 deletions
+4 -4
View File
@@ -73,9 +73,9 @@ jobs:
shell: pwsh
run: |
[string]$injector = (Select-Xml -Path 'Src/SpecterOps.Passkeys.Injector/SpecterOps.Passkeys.Injector.csproj' -XPath '//Version').Node.InnerText
[string]$mythic = (Select-Xml -Path 'Src/SpecterOps.Passkeys.SharpPasskeys/SpecterOps.Passkeys.SharpPasskeys.csproj' -XPath '//Version').Node.InnerText
[string]$sharpPasskeys = (Select-Xml -Path 'Src/SpecterOps.Passkeys.SharpPasskeys/SpecterOps.Passkeys.SharpPasskeys.csproj' -XPath '//Version').Node.InnerText
"INJECTOR_VERSION=$injector" >> $env:GITHUB_OUTPUT
"MYTHIC_VERSION=$mythic" >> $env:GITHUB_OUTPUT
"SHARPPASSKEYS_VERSION=$sharpPasskeys" >> $env:GITHUB_OUTPUT
- name: Upload Injector x64 as Artifact
uses: actions/upload-artifact@v6
@@ -92,11 +92,11 @@ jobs:
- name: Upload WebAuthn Hook as Artifact
uses: actions/upload-artifact@v6
with:
name: WebAuthnHook_v${{ steps.versions.outputs.MYTHIC_VERSION }}
name: WebAuthnHook_v${{ steps.versions.outputs.SHARPPASSKEYS_VERSION }}
path: Build/bin/SpecterOps.Passkeys.SharpPasskeys/release/WebAuthnHook_*.dll
- name: Upload SharpPasskeys CLI as Artifact
uses: actions/upload-artifact@v6
with:
name: SharpPasskeys_v${{ steps.versions.outputs.MYTHIC_VERSION }}
name: SharpPasskeys_v${{ steps.versions.outputs.SHARPPASSKEYS_VERSION }}
path: Build/bin/SpecterOps.Passkeys.SharpPasskeys/release/SharpPasskeys.exe
+2 -2
View File
@@ -69,9 +69,9 @@ jobs:
shell: pwsh
run: |
[string]$injector = (Select-Xml -Path 'Src/SpecterOps.Passkeys.Injector/SpecterOps.Passkeys.Injector.csproj' -XPath '//Version').Node.InnerText
[string]$mythic = (Select-Xml -Path 'Src/SpecterOps.Passkeys.SharpPasskeys/SpecterOps.Passkeys.SharpPasskeys.csproj' -XPath '//Version').Node.InnerText
[string]$sharpPasskeys = (Select-Xml -Path 'Src/SpecterOps.Passkeys.SharpPasskeys/SpecterOps.Passkeys.SharpPasskeys.csproj' -XPath '//Version').Node.InnerText
"INJECTOR_VERSION=$injector" >> $env:GITHUB_OUTPUT
"MYTHIC_VERSION=$mythic" >> $env:GITHUB_OUTPUT
"SHARPPASSKEYS_VERSION=$sharpPasskeys" >> $env:GITHUB_OUTPUT
- name: Create GitHub Release
shell: pwsh
+1 -1
View File
@@ -2,7 +2,7 @@
<!-- C# GUI App -->
<Project Path="Src/SpecterOps.Passkeys.Injector/SpecterOps.Passkeys.Injector.csproj" DefaultStartup="true" />
<!-- Mythic plugin -->
<!-- SharpPasskeys CLI -->
<Project Path="Src/SpecterOps.Passkeys.SharpPasskeys/SpecterOps.Passkeys.SharpPasskeys.csproj" />
<!-- Native WebAuthn API hook DLL -->
+1
View File
@@ -23,6 +23,7 @@
<EnablePackageValidation>true</EnablePackageValidation>
<!-- Assembly metadata -->
<Product>Pass-the-Passkey</Product>
<Authors>Michael Grafnetter</Authors>
<Company>SpecterOps</Company>
<Copyright>Copyright © SpecterOps</Copyright>
@@ -3,6 +3,11 @@
Fetches recent WebAuthn assertion responses from the local or remote computer's Event Log.
.PARAMETER ComputerName
Specifies the name of the computer from which to retrieve recent WebAuthN assertion responses.
.DESCRIPTION
This script can be used to exploit the CVE-2026-34348 vulnerability.
.NOTES
Author: Michael Grafnetter
Version: 1.0
#>
#requires -Version 5.1
+4 -1
View File
@@ -4,7 +4,10 @@
.DESCRIPTION
This script is a quick-and-dirty PoC and should not be used in production environments.
.NOTES
This is a modiefied version of the original script from TokenTactics v2,
Author: Michael Grafnetter
Version: 1.0
This is a modified version of the original script from TokenTactics v2,
created by Fabian Bader.
Repository: https://github.com/f-bader/TokenTacticsV2
#>
@@ -2,12 +2,17 @@
.SYNOPSIS
Monitors the local computer's Event Log for new WebAuthn assertion responses
and optionally suspends the browser process.
.DESCRIPTION
This script can be used to exploit the CVE-2026-34348 vulnerability.
.PARAMETER Suspend
Indicates whether to suspend the browser process that initiated
the authentication request.
.PARAMETER BlockTraffic
Indicates whether to temporarily block outbound network traffic
from the browser process during authentication.
.NOTES
Author: Michael Grafnetter
Version: 1.0
#>
#requires -Version 5.1
@@ -16,9 +16,8 @@
<RootNamespace>SpecterOps.Passkeys.Injector</RootNamespace>
<!-- Assembly metadata -->
<AssemblyTitle>Passkey Injector</AssemblyTitle>
<Product>SpecterOps Passkey Injector</Product>
<AssemblyName>PasskeyInjector</AssemblyName>
<Version>2.6.0</Version>
<Version>2.7.0</Version>
<!-- TypeScript configuration (must be synced with tsconfig.json) -->
<TypeScriptCompileBlocked>false</TypeScriptCompileBlocked>
<TypeScriptToolsVersion>Latest</TypeScriptToolsVersion>
@@ -6,7 +6,7 @@
xmlns:local="clr-namespace:SpecterOps.Passkeys.Injector"
xmlns:wv2="clr-namespace:Microsoft.Web.WebView2.Wpf;assembly=Microsoft.Web.WebView2.Wpf"
mc:Ignorable="d"
Title="SpecterOps Passkey Injector" Height="768" Width="1024" MinHeight="600" MinWidth="800"
Title="Passkey Injector" Height="768" Width="1024" MinHeight="600" MinWidth="800"
Closed="OnWindowClosed"
Icon="pack://application:,,,/Lock.ico">
<Window.Resources>
@@ -2,7 +2,7 @@
namespace SpecterOps.Passkeys.SharpPasskeys;
/// <summary>
/// Entry point for the Passkeys Mythic CLI, a tool for interacting with the Windows WebAuthn API.
/// Entry point for the SharpPasskeys CLI, a tool for interacting with the Windows WebAuthn API.
/// </summary>
public class Program
{
@@ -22,7 +22,7 @@ public class Program
});
ILogger logger = loggerFactory.CreateLogger("Passkeys");
var rootCommand = new RootCommand("SpecterOps Passkeys Mythic CLI")
var rootCommand = new RootCommand("SharpPasskeys CLI")
{
PromptCommand.Create(logger),
WaitCommand.Create(logger),
@@ -10,8 +10,7 @@
<!-- Disable the generation of the config file -->
<AutoGenerateBindingRedirects>false</AutoGenerateBindingRedirects>
<GenerateSupportedRuntime>false</GenerateSupportedRuntime>
<AssemblyTitle>Passkeys CLI</AssemblyTitle>
<Product>SpecterOps Passkeys CLI</Product>
<AssemblyTitle>SharpPasskeys CLI</AssemblyTitle>
<Version>2.7.0</Version>
<!-- CA1848: Use LoggerMessage delegates for performance -->
<!-- CA1873: Avoid expensive logging argument evaluation -->