How to Phish for User Passwords with PowerShell
ID: 14fbcb5b-f916-5808-80b6-d6bbdb4ad8a0
STIX ID: report--14fbcb5b-f916-5808-80b6-d6bbdb4ad8a0
Feed Name: Black Hills Infosec Blog
This report details CredPhish, a PowerShell-based credential-phishing tool that invokes legitimate-looking Windows credential prompts (via the CredentialPicker API) to harvest user passwords and exfiltrate them using DNS queries (Resolve-DnsName) or HTTP requests (ConfigSecurityPolicy.exe). It documents configuration options, demonstration screenshots, capture/reconstruction techniques for intercepted data, persistence via Task Scheduler, and recommended mitigations and detection strategies such as user training and monitoring for suspicious scripting activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
