Quantcast
Channel: DFIR Training - Recently Added Listings
Viewing all articles
Browse latest Browse all 888

CyberGate Keylogger Decryption Tool

$
0
0

Arsenal's CyberGate Keylog Decrypter script is a python tool that can be used against CyberGate encrypted keylogger files (either whole or in part, provided that the individual record is intact) to decode the cipher text and return the original plaintext that was captured by the RAT.

Fragmented entries from the file must start with '####'.

It is assumed that you know what your decryption key is. If you do not know your decryption key, but do have the RAT live/installed on a system you control, a chosen-text attack is a good way to derive the key. Note that '\n' and '\r' are not included in the XOR.


Category: Arsenal Recon
Category URL: http://www.dfir.training/component/mtree/by-developer/arsenal-recon?Itemid=

Viewing all articles
Browse latest Browse all 888

Trending Articles