Vanara.PInvoke.CldApi[10] comctl32.dll Vanara.PInvoke.ComCtl32[11] ComDlg32.dll Vanara.PInvoke.ComDlg32[12] credui.dll Vanara.PInvoke.CredUI[13] crypt32.dll, bcrypt.dll, ncrypt.dll, tokenbinding.dll, cryptui.dll, cryptnet.dll https://github.com/dahall/Vanara/blob/master/PInvoke/ComDlg32/CorrelationReport.md [13] Vanara.PInvoke.CredUI : https://github.com/dahall/Vanara/blob/master/PInvoke/CredUI/CorrelationReport.md [14] Vanara.PInvoke.Cryptography
shell32.lib ole32.lib oleaut32.lib user32.lib uuid.lib odbc32.lib odbccp32.lib delayimp.lib credui.lib
本地管理员账户枚举主要信赖的是注册表项:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\CredUI\EnumerateAdministrators
47A1-ACC4-8EABE61B0B54} - Easconsent.dll {924DC564-16A6-42EB-929A-9A61FA7DA06F} - Authentication UI CredUI
hr = E_OUTOFMEMORY; } break; case CPUS_CHANGE_PASSWORD: case CPUS_CREDUI
CredUIPromptForCredentials收集凭据 窃取用户凭据 #include <iostream> #include <Windows.h> #include <wincred.h> #pragma comment(lib, "Credui.lib