Exposing RDP Credentials Using Rc7Hook API Hooking.
RdpVandalist uses Rc7Hook API hooking library to install patchless hooks on APIs like CredIsMarshaledCredentialW and CryptProtectMemory to extract RDP credentials easily, Saving them to a global structure similar to RdpThief's method.