Pillaging
What’s Pillaging ?
Scenario

Installed Applications
Identifying Common Applications
use PowerShell and read the Windows registry
mRemoteNG
Discover mRemoteNG Configuration Files
Display confCons.xml
Decrypt the Password with mremoteng_decrypt
Decrypt With master password
For Loop to Crack the Master Password with mremoteng_decrypt
Abusing Cookies to Get Access to IM Clients
Cookie Extraction from Firefox
Copy Firefox Cookies Database
Extract Slack Cookie from Firefox Cookies Database

Cookie Extraction from Chromium-based Browsers
PowerShell Script - Invoke-SharpChromium
Copy Cookies to SharpChromium Expected Location
Invoke-SharpChromium Cookies Extraction
Clipboard
Monitor the Clipboard with PowerShell
Roles and Services
Attacking Backup Servers
restic - Initialize Backup Directory
restic - Back up a Directory
restic - Back up a Directory with VSS
restic - Check Backups Saved in a Repository
restic - Restore a Backup with ID
Last updated