Event JSON
{
"id": "ecddbbb698dfa7a1a66e4a5e619a46de62eba98b6830d7a1373f4ae08accc716",
"pubkey": "758c17dd844b7702107be6aa2045c6a9b1f27c1014a5fdbcdf9829dd70b17e82",
"created_at": 1787108523,
"kind": 1,
"tags": [
[
"t",
"infosec"
],
[
"t",
"tool"
],
[
"t",
"vhdvomit"
],
[
"t",
"vbkvomit"
],
[
"t",
"veeamthief"
],
[
"imeta",
"url https://mastodon.ml/system/media_attachments/files/117/119/940/584/692/874/original/1248b8fb0e1d5e43.jpg",
"m image/jpeg",
"dim 759x929",
"blurhash U77^_V?bIUxu_3x]M{t7~qxuIUt7?bxuRjof"
],
[
"imeta",
"url https://mastodon.ml/system/media_attachments/files/117/119/940/929/734/183/original/032e245d6c9b39c3.jpg",
"m image/jpeg",
"dim 2292x1430",
"blurhash U67nUf~qxuM{-;?bxuRj?b-;t7Rj%Mt7ofWB"
],
[
"proxy",
"https://mastodon.ml/users/ashed/statuses/117119944226416537",
"activitypub"
]
],
"content": "VHDVomit (https://github.com/mattmillen15/VHDVomit)\n\nA tool to search SMB shares for VHD/VMDK/VHDX backup files, mount them and dump sensitive data including NTDS.dit, SYSTEM, and SAM hives.\n\nvbkVomit (https://github.com/mattmillen15/vbkVomit)\n\nExtract hashes from Veeam .vbk backup. Reads the VBK directly, finds the NTFS volume inside, walks the MFT, reassembles ntds.dit + SAM/SECURITY/SYSTEM, and runs impacket secretsdump.\n\nVeeamThief (https://github.com/mattmillen15/VeeamThief)\n\nRogue vSphere server for capturing Veeam Backup \u0026 Replication credentials.\n\nBlog: https://adversaryco.com/blog/breaking-bad-backups\n\n#infosec #tool #vhdvomit #vbkVomit #VeeamThief\n\nhttps://mastodon.ml/system/media_attachments/files/117/119/940/584/692/874/original/1248b8fb0e1d5e43.jpg\nhttps://mastodon.ml/system/media_attachments/files/117/119/940/929/734/183/original/032e245d6c9b39c3.jpg",
"sig": "e982f2514c0a510d983b6cb625c69954d215c525d0fe84ed7a095e9aa01d468c03fe3c4c17e63472b3e008e2e0184aed70137f947253d8b113e098bc2a960a30"
}