Arvanaghi/SessionGopher
SessionGopher is a PowerShell tool that uses WMI to extract saved session information for remote access tools such as WinSCP, PuTTY, SuperPuTTY, FileZilla, and Microsoft Remote Desktop. It can be run remotely or locally. observed · 2026-08-28
Health v2 · maintenance only
32/100
- Activity 0
- Release rhythm 35
- Longevity 100
Flags: no_releases no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 3465
- days_rel: n/a
- days_push: 1380
- n_releases_24m: 0
Adoption not part of the score
1334 stars · 170 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
SessionGopher is a PowerShell tool that extracts and decrypts saved session information for remote access tools like WinSCP, PuTTY, SuperPuTTY, FileZilla, and RDP. It queries the registry via WMI and can run locally or remotely against lists of hosts or entire domains.
Use cases
- extract saved PuTTY and WinSCP session credentials from Windows hosts
- find systems that connect to jump boxes or Unix servers during a pentest
- remotely harvest saved RDP and FileZilla sessions across a domain
- search drives for .ppk, .rdp, and .sdtid files in thorough mode
- dump saved session passwords from registry hives
When to choose
- you are doing red-team or post-exploitation work on Windows environments
- you need to map lateral movement paths through saved remote-access sessions
- you want a lightweight PowerShell script with no dependencies that runs via WMI
When to avoid
- you need a maintained tool with active development or support
- you are not on Windows or cannot run PowerShell
- you need stealth features or evasion capabilities beyond quiet WMI queries
Facets
cli-tool · maturity maintenance
security penetration-testing cli security penetration-testing windows developer-tools windows cli powershell red-team credential-extraction wmi registry remote-access-tools post-exploitation
1 source
- readme: https://github.com/Arvanaghi/SessionGopher · fetched 2026-08-28 · aad4f6f56f12
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| Arvanaghi/SessionGopher | main | 32 |
For agents
markdown · JSON · MCP: product_card(name="Arvanaghi/SessionGopher")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem