Post/aux modules for Recall collection
Summary
We probably want to include collection, parsing, and analysis of Recall data la this netexec PR or the totalrecall script.
Basic example
- Connect over RPC to remote windows machine/get a session (post version)
- Enumerate/qualify Recall state and storage locations
- Collect contents of storage and relevant registry/database info for access
- Parse and extract recall data
- Report notes, creds, and other useful information while storing parsed loot and (optionally) entire collected sample
Motivation
Because
Looks like @xaitax already pretty much did that? https://x.com/xaitax/status/1799140614241501550
I will check what's required in terms of changes or if feasible at all on the 18th. 👍🏻 No point adding it now anymore.
This sounds cool; Is it a useful module still with the recent news? 👀
Hi @adfoster-r7
This sounds cool; Is it a useful module still with the recent news? 👀
I have the new CoPilot+ laptop and once they roll Recall out in the Insider channel I will work on version 2 of my TotalRecall script as well as adjusting my MSF module (as shown above).
Cheers, Alex