CredPhish - A PowerShell Script Designed To Invoke Legitimate Credential Prompts And Exfiltrate Passwords Over DNS
CredPhish is a PowerShell script designed to invoke credential prompts and exfiltrate passwords. It relies on CredentialPicker to collect user passwords, Resolve-DnsName for DNS exfiltration, and Windows Defender's ConfigSecurityPolicy.exe to perform arbitrary GET requests.
For a walkthrough, see the Black Hills Infosec publication.
Via: feedproxy.google.com
CredPhish - A PowerShell Script Designed To Invoke Legitimate Credential Prompts And Exfiltrate Passwords Over DNS
Reviewed by Anónimo
on
17:40
Rating:
![CredPhish - A PowerShell Script Designed To Invoke Legitimate Credential Prompts And Exfiltrate Passwords Over DNS](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgtBzoGk-4TY3IxkvxrqOKomstsJJruUcqH4ZKzCoJYbo-5nd26ejL34V5mAVdyCtKL9XwUVhYE5Oi5zvz8Fnms08ytApngyIrjS-UPigUscYmx7yNCI5-NWfLwAXI5elLChWqyiGFEN1el/s72-w640-c-h272/CredPhish_1_credphish-752010.gif)