- Notifications
You must be signed in to change notification settings - Fork45
CredPhish is a PowerShell script designed to invoke legitimate credential prompts and exfiltrate passwords over DNS.
NotificationsYou must be signed in to change notification settings
tokyoneon/CredPhish
Folders and files
Name | Name | Last commit message | Last commit date | |
---|---|---|---|---|
Repository files navigation
CredPhish is a PowerShell script designed to invoke credential prompts and exfiltrate passwords. It relies onCredentialPicker to collect user passwords,Resolve-DnsName for DNS exfiltration, and Windows Defender'sConfigSecurityPolicy.exe to perform arbitrary GET requests.
For a walkthrough, see theBlack Hills Infosec publication.
About
CredPhish is a PowerShell script designed to invoke legitimate credential prompts and exfiltrate passwords over DNS.
Topics
Resources
Stars
Watchers
Forks
Releases
No releases published