Saturday, June 17, 2017

mimikittenz – Extract Plain-Text Passwords From Memory

7:59 AM Leave a Reply
mimikittenz – Extract Plain-Text Passwords From Memory
mimikittenz is a post-exploitation powershell tool that utilizes the Windows function ReadProcessMemory() in order to extract plain-text passwords from various target processes.
mimikittenz - Extract Plain-Text Passwords From Memory
The aim of mimikittenz is to provide user-level (non-admin privileged) sensitive data extraction in order to maximise post exploitation efforts and increase value of information gathered per target.
NOTE: This tool is targeting running process memory address space, once a process is killed it’s memory ‘should’ be cleaned up and inaccessible however there are some edge cases in which this does not happen.

Features

Currently mimikittenz is able to extract the following credentials from memory:

Webmail
  • Gmail
  • Office365
  • Outlook Web
Accounting
  • Xero
  • MYOB
Remote Access
  • Juniper SSL-VPN
  • Citrix NetScaler
  • Remote Desktop Web Access 2012
Development
  • Jira
  • Github
  • Bugzilla
  • Zendesk
  • Cpanel
IHateReverseEngineers
  • Malwr
  • VirusTotal
  • AnubisLabs
Misc
  • Dropbox
  • Microsoft Onedrive
  • AWS Web Services
  • Slack
  • Twitter
  • Facebook
You can download mimikittenz here: