{"id":21230375,"url":"https://github.com/idov31/mrkaplan","last_synced_at":"2025-04-09T15:08:49.990Z","repository":{"id":40386747,"uuid":"474458820","full_name":"Idov31/MrKaplan","owner":"Idov31","description":"MrKaplan is a tool aimed to help red teamers to stay hidden by clearing evidence of execution.","archived":false,"fork":false,"pushed_at":"2023-09-26T18:09:29.000Z","size":1873,"stargazers_count":258,"open_issues_count":0,"forks_count":47,"subscribers_count":13,"default_branch":"master","last_synced_at":"2025-04-09T15:08:46.130Z","etag":null,"topics":["attack","cyber","cybersecurity","evasion","infosec","infosectools","powershell","red-team","red-teaming","security","security-tools","windows"],"latest_commit_sha":null,"homepage":"","language":"PowerShell","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"gpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/Idov31.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2022-03-26T20:26:34.000Z","updated_at":"2025-03-05T20:09:44.000Z","dependencies_parsed_at":"2024-11-28T02:32:51.399Z","dependency_job_id":"955a7e16-7b91-4582-a751-41bf1f0b0844","html_url":"https://github.com/Idov31/MrKaplan","commit_stats":null,"previous_names":[],"tags_count":5,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Idov31%2FMrKaplan","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Idov31%2FMrKaplan/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Idov31%2FMrKaplan/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Idov31%2FMrKaplan/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/Idov31","download_url":"https://codeload.github.com/Idov31/MrKaplan/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":248055282,"owners_count":21040157,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["attack","cyber","cybersecurity","evasion","infosec","infosectools","powershell","red-team","red-teaming","security","security-tools","windows"],"created_at":"2024-11-20T23:37:45.712Z","updated_at":"2025-04-09T15:08:49.963Z","avatar_url":"https://github.com/Idov31.png","language":"PowerShell","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Mr.Kaplan\n\n![image](https://img.shields.io/badge/powershell-5391FE?style=for-the-badge\u0026logo=powershell\u0026logoColor=white) ![image](https://img.shields.io/badge/Windows-0078D6?style=for-the-badge\u0026logo=windows\u0026logoColor=white)\n\n## Description\n\nMrKaplan is a tool aimed to help red teamers to stay hidden by clearing evidence of execution. It works by saving information such as the time it ran, snapshot of files and associate each evidence to the related user.\n\nThis tool is inspired by [MoonWalk](https://github.com/mufeedvh/moonwalk), a similar tool for Unix machines.\n\nYou can read more about it in the [wiki](https://github.com/idov31/MrKaplan/wiki) page.\n\n## Features\n\n- Stopping event logging.\n- Clearing files artifacts.\n- Clearing registry artifacts.\n- Can run for multiple users.\n- Can run as user and as admin (Highly recommended to run as admin).\n- Can save timestamps of files.\n- Can exclude certain operations and leave artifacts to blue teams.\n\n## Usage\n\n- Before you start your operations on the computer, run MrKaplan with begin flag and whenever your finish run it again with an end flag.\n- ***DO NOT REMOVE MrKaplan-Config.json file until you rerun with the end flag***, otherwise, MrKaplan will not be able to use the information.\n\u003cimg src=\"Pictures/usage.png\" /\u003e\n\n## IOCs\n\n- Powershell process that access to the artifacts mentioned in the wiki page.\n\n- Powershell importing weird base64 blob.\n\n- Powershell process that performs Token Manipulation.\n\n- MrKaplan's registry key: HKCU:\\Software\\MrKaplan.\n\n## Acknowledgements\n\n- [PowerSploit](https://github.com/PowerShellMafia/PowerSploit)\n\n- [Phant0m](https://github.com/hlldz/Phant0m)\n\n- [ForensicArtifacts](https://github.com/ForensicArtifacts/artifacts/blob/main/data/windows.yaml)\n\n## Disclaimer\n\nI'm not responsible in any way for any kind of damage that is done to your computer / program as cause of this project. I'm happily accept contribution, make a pull request and I will review it!\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fidov31%2Fmrkaplan","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fidov31%2Fmrkaplan","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fidov31%2Fmrkaplan/lists"}