{"repo":"GoSecure/pyrdp","free":true,"listed":false,"github":"https://github.com/GoSecure/pyrdp","clone":"git clone https://github.com/GoSecure/pyrdp.git","description":"RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact","language":"Python","stars":1775,"topics":["hacktoberfest","rdp","pentest","honeypot","mitm","pyrdp","security"],"license":"GPL-3.0","category":"security-tools","readme_excerpt":"PyRDP PyRDP is a Python Remote Desktop Protocol (RDP) Monster-in-the-Middle (MITM) tool and library. It features a few tools: - RDP Monster-in-the-Middle - Logs plaintext credentials or NetNTLM hashes used when connecting - Steals data copied to the clipboard - Saves a copy of the files transferred over the network - Crawls shared drives in the background and saves them locally - Saves replays of connections so you can look at them later - Runs console commands or PowerShell payloads automatically on new connections - RDP Player: - See live RDP connections coming from the MITM - View replays of RDP connections - Take control of active RDP sessions while hiding your actions - List the client's mapped drives and download files from them during active sessions - Converter tool: - Convert RDP replays to videos for easier sharing - Convert RDP replays to a sequence of low-level events serialized in JSON format - Convert PCAPs to replays, videos or JSON events - Convert decrypted PCAPs (L7 PDUs) to replays, videos or JSON events - RDP Certificate Cloner: - Create a self-signed X509 certificate with the same fields as an RDP server's certificate PyRDP was introduced in 2018 in which we demonstrated that we can catch a real threat actor in action. This tool is being developed with both pentest and malware research use cases in mind. Table of Contents Supported Systems Installing Using pipx Using the Docker Image Using PyRDP Using the PyRDP Monster\\-in\\-the\\-Middle Using the PyRDP Pla","default_branch":null,"files":null,"tree":[],"storefront":"/r/GoSecure","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/GoSecure/pyrdp/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}