
Shared Import Table Ties Four AD Attack Tools to One Build Pipeline
A single imphash links SharpHound, Certify, Rubeus, and DefenderCheck across eight files, while a full Mimikatz suite and matched SafetyKatz forks round out a complete discovery-to-evasion Active Directory toolkit. Build-provenance signals — not tool names — reveal a professionally packaged kit assembled from public GitHub tools.
A single .NET import-table fingerprint — imphash f34d5f2d4577ed6d9ceec516c1f5a744 — turns up on eight separate files carrying four different public tool identities: SharpHound, Certify, Rubeus, DefenderCheck, and an unlabeled dropper masquerading as RandomName.exe. None of these tools were written by the same author, and none share a codebase.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read