logo

Intercepting passwords with Empire and winning!

ID: c580cfd9-601e-5d1b-840a-634a3bf0400d

STIX ID: report--c580cfd9-601e-5d1b-840a-634a3bf0400d

Feed Name: SensePost Blog

Date Published: 2016-11-18

Date Updated: 2026-04-29

...
...

This blog post outlines a red-team technique for capturing newly changed Active Directory passwords by reflectively injecting a statically linked `HookPasswordChange.dll` into `lsass.exe` using Empire’s `Invoke-ReflectivePEInjection`, then exfiltrating credentials to a Metasploit `auxiliary/server/capture/http_basic` listener; it emphasizes x64-only constraints, correct process targeting, and configuration steps rather than describing a specific incident.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.