SessionGopher – Session Extraction Tool

Outsmart Malicious Hackers


SessionGopher is a PowerShell Session Extraction tool that uses WMI to extract saved session information for remote access tools such as WinSCP, PuTTY, SuperPuTTY, FileZilla, and Microsoft Remote Desktop.

SessionGopher - Session Extraction Tool

The tool can find and decrypt saved session information for remote access tools. It has WMI functionality built in so it can be run remotely, its best use case is to identify systems that may connect to Unix systems, jump boxes, or point-of-sale terminals.

How it Works

SessionGopher works by querying the HKEY_USERS hive for all users who have logged onto a domain-joined box at some point. It extracts PuTTY, WinSCP, SuperPuTTY, FileZilla, and RDP saved session information. It automatically extracts and decrypts WinSCP, FileZilla, and SuperPuTTY saved passwords.

When run in Thorough mode, it also searches all drives for PuTTY private key files (.ppk) and extracts all relevant private key information, including the key itself, as well as for Remote Desktop (.rdp) and RSA (.sdtid) files.

Usage

You can download SessionGopher here:

SessionGopher.ps1

Or read more here.


Posted in: Hacking Tools, Windows Hacking

, , , , , , , , , , ,

Recent in Hacking Tools:
- SessionGopher – Session Extraction Tool
- Powerfuzzer – Automated Customizable Web Fuzzer
- Angry IP Scanner – Fast Network Scanner

Related Posts:

Most Read in Hacking Tools:
- Top 15 Security/Hacking Tools & Utilities - 2,014,960 views
- Brutus Password Cracker – Download brutus-aet2.zip AET2 - 1,568,647 views
- wwwhack 1.9 – Download wwwhack19.zip Web Hacking Tool - 700,397 views


No comments yet.

Leave a Reply