10 years ago, my colleague Yannick published #pywerview. I was an early adopter and later became an official co-maintainer. I still use it on every pentest. Nowadays, a project like that could probably be vibe-coded in no time by burning tokens, but it was a great adventure.
drm
@AlmondOffSec@infosec.exchange but #pywerview at night
(near) Instant dumping of the Bitlocker VMK using Sipeed #SLogic16U3 and #ngscopeclient 🥰. Full disclosure: i know nothing about C++, filter was fully vibe coded (with a Claude free plan)
I was bored to type the same commands each time I started a new internal pentest. So here comes KingCastle. This script does not perform any attacks, consider it as a cheat sheet, to quickly see low hanging fruits.
https://github.com/ThePirateWhoSmellsOfSunflowers/KingCastle
To all my VMK sniffers here: you can now perform the attack for approximately 80€. I've successfully sniffed my good ol' T470 with a 16u3 from SipeedIO. The hardware is nice🫡, the software is meh😕(laggy/ buggy/crash). Definitively not a Saleae killer, but ok to start to play.
4 channels @ 800 MS/s for < 80€ ? 🥰
TPM sniffing is cheaper than ever
https://www.cnx-software.com/2025/11/12/69-sipeed-slogic16u3-low-cost-logic-analyzer-supports-3-2-gbps-bandwidth-150-protocols/
Recently, a colleague encountered a strange situation: an undetermined security product was killing LDAP connections performed by ldap3 (NTLM). A simple bypass was to force SIMPLE authentication (pun intended). I've implemented it in #pywerview.
https://github.com/the-useless-one/pywerview/tree/develop
🌻