Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
21 changes: 18 additions & 3 deletions src/TabExpansion.ps1
Original file line number Diff line number Diff line change
Expand Up @@ -27,18 +27,20 @@ $mimikatzParams = @{
'crypto::certtohw' = '/store: /name: /csp: /pin:'
'crypto::hash' = '/password: /user: /count:'
'crypto::keys' = '/export /provider: /providerype: /cngprovider: /machine /silent'
'crypto::scauth' = '/caname: /upn: /pfx: /castore: /hw /csp: /pin: /nostore /crldp:'
'crypto::scauth' = '/caname: /upn: /pfx: /castore: /hw /csp: /pin: /nostore /crldp: /keysize: /cahash: /cn: /o: /ou: /c:'
'crypto::stores' = '/systemstore:'
'crypto::system' = '/export /file:'
'dpapi::blob' = '/in: /out: /unprotect /masterkey: /password: /entropy: /prompt /machine'
'dpapi::blob' = '/in: /raw: /out: /ascii /unprotect /masterkey: /password: /entropy: /prompt /machine'
'dpapi::cache' = '/file: /flush /load /save'
'dpapi::capi' = '/in: /unprotect /masterkey: /password: /entropy: /prompt /machine'
'dpapi::chrome' = '/in: /unprotect /masterkey: /password: /entropy: /prompt /machine'
'dpapi::cng' = '/in: /unprotect /masterkey: /password: /entropy: /prompt /machine'
'dpapi::cred' = '/in: /unprotect /masterkey: /password: /entropy: /prompt /machine'
'dpapi::credhist' = '/in: /sid: /password: /sha1:'
'dpapi::luna' = '/client: /hive: /unprotect /masterkey: /password: /entropy: /prompt /machine'
'dpapi::masterkey' = '/in: /protected /sid: /hash: /system: /password: /pvk: /rpc /dc: /domain:'
'dpapi::protect' = '/data: /description: /entropy: /machine /system /prompt /c /out:'
'dpapi::ps' = '/in: /unprotect /masterkey: /password: /entropy: /prompt /machine'
'dpapi::rdg' = '/in: /unprotect /masterkey: /password: /entropy: /prompt /machine'
'dpapi::ssh' = '/hive: /impersonate /unprotect /masterkey: /password: /entropy: /prompt /machine'
'dpapi::vault' = '/cred: /policy: /unprotect /masterkey: /password: /entropy: /prompt /machine'
Expand All @@ -53,17 +55,19 @@ $mimikatzParams = @{
'kerberos::hash' = '/password: /user: /domain: /count:'
'kerberos::list' = '/export'
'lsadump::bkey' = '/system: /export /secret /guid:'
'lsadump::cache' = '/user: /password: /ntlm: /subject: /system: /security:'
'lsadump::cache' = '/user: /password: /ntlm: /subject: /system: /security: /dcc:'
'lsadump::changentlm' = '/oldpassword: /oldntlm: /newpassword: /newntlm: /server: /user: /rid:'
'lsadump::dcshadow' = '/object: /domain: /attribute: /value: /clean /multiple /replOriginatingUid: /replOriginatingUsn: /replOriginatingTime: /dynamic /dc: /computer: /push /stack /viewstack /clearstack /manualregister /manualpush /manualunregister /addentry /remotemodify /viewreplication /kill: /config /schema /root'
'lsadump::dcsync' = '/all /user: /guid: /domain: /dc: /altservice: /export /csv'
'lsadump::lsa' = '/patch /inject /id: /user:'
'lsadump::mbc' = ''
'lsadump::netsync' = '/dc: /user: /ntlm: /account: /computer:'
'lsadump::rpdata' = '/system: /name: /export /secret'
'lsadump::sam' = '/system: /sam:'
'lsadump::secrets' = '/system: /security:'
'lsadump::setntlm' = '/password: /ntlm: /server: /user: /rid:'
'lsadump::trust' = '/system: /patch'
'misc::lock' = '/process:'
'misc::skeleton' = '/letaes'
'misc::wp' = '/file: /process:'
'net::deleg' = '/dns /server:'
Expand All @@ -84,6 +88,14 @@ $mimikatzParams = @{
'sid::lookup' = '/sid: /name: /system:'
'sid::modify' = '/sam: /sid: /new: /system:'
'sid::query' = '/sam: /sid: /system:'
'sr98::beep' = ''
'sr98::raw' = '/wipe /b0: /b1: /b2: /b3: /b4: /b5: /b6: /b7:'
'sr98::b0' = '/b0:'
'sr98::list' = ''
'sr98::hid' = '/fc: /cn:'
'sr98::em4100' = '/read /id:'
'sr98::noralsy' = '/year: /id:'
'sr98::nedap' = '/long /sub: /cc: /cn:'
'standard::base64' = '/in /out'
'standard::log' = '/stop'
'standard::version' = '/full /cab'
Expand Down Expand Up @@ -193,6 +205,9 @@ $mimikatzParamValues = @{
'lsadump::trust' = @{
'system' = { Expand-ADDomainControllerFQDN -Filter $args[0] }
}
'misc::lock' = @{
'process' = { Expand-ProcessName -Filter $args[0] }
}
'misc::wp' = @{
'process' = { Expand-ProcessName -Filter $args[0] }
}
Expand Down