Intercepting passwords with Empire and winning!
ID: c580cfd9-601e-5d1b-840a-634a3bf0400d
STIX ID: report--c580cfd9-601e-5d1b-840a-634a3bf0400d
Feed Name: SensePost Blog
This blog post outlines a red-team technique for capturing newly changed Active Directory passwords by reflectively injecting a statically linked `HookPasswordChange.dll` into `lsass.exe` using Empire’s `Invoke-ReflectivePEInjection`, then exfiltrating credentials to a Metasploit `auxiliary/server/capture/http_basic` listener; it emphasizes x64-only constraints, correct process targeting, and configuration steps rather than describing a specific incident.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
