Octoberfest7 / SilentHarvest_BOF
PublicA Cobalt Strike BOF implementation of the SilentHarvest registry dumping technique
SilentHarvest is a specialized tool for security testers that extracts password hashes from local accounts, machine credentials, and LSA secrets stored in Windows registry without needing full system control.
How It Works
You learn about SilentHarvest from security blogs or forums, a clever way for testers to uncover hidden passwords on Windows machines.
You grab the files and set everything up in your testing setup so it's prepared to use.
With admin access on the test computer, you run the tool and it quietly finds and shows password codes and hidden info from the system's storage.
You see a clear list of usernames with their password hashes, service logins, and other sensitive details ready for analysis.
Save the codes and use a cracking program to try guessing the real passwords.
Examine the info to understand risks and make the system stronger.
You've successfully extracted and reviewed the hidden credentials, helping improve security on the test machine.
Star Growth
Repurpose is a Pro feature
Generate ready-to-use prompts for X threads, LinkedIn posts, blog posts, YouTube scripts, and more -- with full repo context baked in.
Unlock RepurposeSimilar repos coming soon.