remotecache.py

66

DFIR Tools

License Type
Free
Cryptography and Encryption
Password Cracking
This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to extract juicy information such as LAPS passwords or any sensitive information on the screen. Blue Team member can reconstruct PNG files to see what an attacker did on a compromised host. It is extremely useful for a forensics team to extract timestamps after an attack on a host to collect evidences and perform further analysis.

User comments

There are no user comments for this listing.
Already have an account? or Create an account