logo

How to Phish for User Passwords with PowerShell

ID: 14fbcb5b-f916-5808-80b6-d6bbdb4ad8a0

STIX ID: report--14fbcb5b-f916-5808-80b6-d6bbdb4ad8a0

Feed Name: Black Hills Infosec Blog

Threat Score
70/100

Date Published: 2021-07-27

Date Updated: 2026-04-27

Author: BHIS

...
...

This report details CredPhish, a PowerShell-based credential-phishing tool that invokes legitimate-looking Windows credential prompts (via the CredentialPicker API) to harvest user passwords and exfiltrate them using DNS queries (Resolve-DnsName) or HTTP requests (ConfigSecurityPolicy.exe). It documents configuration options, demonstration screenshots, capture/reconstruction techniques for intercepted data, persistence via Task Scheduler, and recommended mitigations and detection strategies such as user training and monitoring for suspicious scripting activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.