{"adoption": {"forks": 361, "observed_at": "2026-08-28T04:04:49.055130+00:00", "stars": 1469}, "canonical_url": "https://ross.abutalabs.com/products/rdpthief", "card": {"archived": false, "artifact_type": "library", "description": "Extracting Clear Text Passwords from mstsc.exe using API Hooking.", "domain": ["security", "penetration-testing", "windows"], "enriched": true, "function": ["security", "cryptography", "developer-tools"], "health_score": 20, "homepage": null, "language": "C++", "license": null, "license_family": "other", "maturity": "maintenance", "member_repos": ["0x09AL/RdpThief"], "name": "0x09AL/RdpThief", "platform": ["windows", "cpp"], "pushed_at": "2024-07-20T06:58:02+00:00", "repo": "0x09AL/RdpThief", "stars": 1469, "tags": ["red-team", "credential-harvesting", "api-hooking", "dll-injection", "rdp", "cobalt-strike", "offensive-security"], "topics": ["redteaming", "cpp", "pentesting-windows", "api-hooking"], "urls": [], "use_cases": ["extract clear-text passwords from mstsc.exe during red team engagements", "hook Windows API calls in the RDP client to capture credentials", "inject shellcode into mstsc.exe processes automatically", "dump captured RDP credentials from a Cobalt Strike session", "demonstrate credential theft risks from remote desktop clients"], "what_it_is": "RdpThief is a standalone DLL that, when injected into the mstsc.exe (Remote Desktop client) process, uses API hooking to extract clear-text credentials and save them to a file. It includes a Cobalt Strike aggressor script that manages injection by monitoring for new mstsc.exe processes and converting the DLL to shellcode via sRDI.", "when_to_avoid": ["you need a defensive or detection tool rather than an offensive one", "your target platform is not Windows", "you require a maintained tool with an active license and ongoing support", "credential harvesting is not permitted in your engagement scope"], "when_to_choose": ["you are running an authorized red team or penetration test on Windows environments", "you need to demonstrate the impact of credential theft from RDP clients", "you want a Cobalt Strike-integrated tool for harvesting mstsc.exe credentials"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/rdpthief", "repo": "0x09AL/RdpThief", "role": "main", "score": 32}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:04:49.055130+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T04:34:51.555684+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "beeef9de0ef45d328fad9cbf3c5cd65c677d64c82c8ff3465ad1c09b2d6b835a", "fetched_at": "2026-08-28T04:04:49.055130+00:00", "kind": "readme", "missing": false, "url": "https://github.com/0x09AL/RdpThief"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:04:49.055130+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T04:34:51.555684+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "beeef9de0ef45d328fad9cbf3c5cd65c677d64c82c8ff3465ad1c09b2d6b835a", "fetched_at": "2026-08-28T04:04:49.055130+00:00", "kind": "readme", "missing": false, "url": "https://github.com/0x09AL/RdpThief"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T04:34:51.555684+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "beeef9de0ef45d328fad9cbf3c5cd65c677d64c82c8ff3465ad1c09b2d6b835a", "fetched_at": "2026-08-28T04:04:49.055130+00:00", "kind": "readme", "missing": false, "url": "https://github.com/0x09AL/RdpThief"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:04:49.055130+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:04:49.055130+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:04:49.055130+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T04:34:51.555684+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "beeef9de0ef45d328fad9cbf3c5cd65c677d64c82c8ff3465ad1c09b2d6b835a", "fetched_at": "2026-08-28T04:04:49.055130+00:00", "kind": "readme", "missing": false, "url": "https://github.com/0x09AL/RdpThief"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:04:49.055130+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:04:49.055130+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T04:34:51.555684+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "beeef9de0ef45d328fad9cbf3c5cd65c677d64c82c8ff3465ad1c09b2d6b835a", "fetched_at": "2026-08-28T04:04:49.055130+00:00", "kind": "readme", "missing": false, "url": "https://github.com/0x09AL/RdpThief"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:04:49.055130+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:04:49.055130+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:04:49.055130+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T04:34:51.555684+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "beeef9de0ef45d328fad9cbf3c5cd65c677d64c82c8ff3465ad1c09b2d6b835a", "fetched_at": "2026-08-28T04:04:49.055130+00:00", "kind": "readme", "missing": false, "url": "https://github.com/0x09AL/RdpThief"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:04:49.055130+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:04:49.055130+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T04:34:51.555684+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "beeef9de0ef45d328fad9cbf3c5cd65c677d64c82c8ff3465ad1c09b2d6b835a", "fetched_at": "2026-08-28T04:04:49.055130+00:00", "kind": "readme", "missing": false, "url": "https://github.com/0x09AL/RdpThief"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T04:34:51.555684+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "beeef9de0ef45d328fad9cbf3c5cd65c677d64c82c8ff3465ad1c09b2d6b835a", "fetched_at": "2026-08-28T04:04:49.055130+00:00", "kind": "readme", "missing": false, "url": "https://github.com/0x09AL/RdpThief"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T04:34:51.555684+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "beeef9de0ef45d328fad9cbf3c5cd65c677d64c82c8ff3465ad1c09b2d6b835a", "fetched_at": "2026-08-28T04:04:49.055130+00:00", "kind": "readme", "missing": false, "url": "https://github.com/0x09AL/RdpThief"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T04:34:51.555684+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "beeef9de0ef45d328fad9cbf3c5cd65c677d64c82c8ff3465ad1c09b2d6b835a", "fetched_at": "2026-08-28T04:04:49.055130+00:00", "kind": "readme", "missing": false, "url": "https://github.com/0x09AL/RdpThief"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 0, "longevity": 100, "rhythm": 35}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": ["no_releases", "no_license"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 2495, "days_push": 774, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 32, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}