Pillaging
Installed Applications
C:\>dir "C:\Program Files"
Volume in drive C has no label.
Volume Serial Number is 900E-A7ED
Directory of C:\Program Files
07/14/2022 08:31 PM <DIR> .
07/14/2022 08:31 PM <DIR> ..
05/16/2022 03:57 PM <DIR> Adobe
05/16/2022 12:33 PM <DIR> Corsair
05/16/2022 10:17 AM <DIR> Google
05/16/2022 11:07 AM <DIR> Microsoft Office 15
07/10/2022 11:30 AM <DIR> mRemoteNG
07/13/2022 09:14 AM <DIR> OpenVPN
07/19/2022 09:04 PM <DIR> Streamlabs OBS
07/20/2022 07:06 AM <DIR> TeamViewer
0 File(s) 0 bytes
16 Dir(s) 351,524,651,008 bytes freemRemoteNG
Hardcoded master password, mR3m
confCons.xml
custom password
Brute force:
Cookies - Slack
Firefox


Chrome
For more tools - See Post Exploit - Browsers Cookies
Modify the code of SharpChromium or copy the cookie file to where SharpChromium is looking.
Clipboard
Attacking Backup Servers
restic
Back up a Directory
To back up a directory such as C:\Windows, which has some files actively used by the operating system, we can use the option --use-fs-snapshot to create a VSS (Volume Shadow Copy) to perform the backup
Check Backups Saved in a Repository
Restore a Backup with ID
Last updated