mirror of
https://github.com/GhostPack/SharpDPAPI
synced 2026-06-08 11:11:23 +00:00
Version 1.7.0
-Landed @leftp's PR for user and machine certificate private key extraction -Added cert triage to the "triage" and "machinetriage" commands -Using /password:X now causes the DPAPI masterkey cache to be output
This commit is contained in:
@@ -7,7 +7,7 @@ namespace SharpDPAPI.Commands
|
||||
|
||||
public class Certificate : ICommand
|
||||
{
|
||||
public static string CommandName => "certificate";
|
||||
public static string CommandName => "certificates";
|
||||
|
||||
public void Execute(Dictionary<string, string> arguments)
|
||||
{
|
||||
|
||||
@@ -10,13 +10,29 @@ namespace SharpDPAPI.Commands
|
||||
|
||||
public void Execute(Dictionary<string, string> arguments)
|
||||
{
|
||||
Console.WriteLine("\r\n[*] Action: Machine DPAPI Credential and Vault Triage\r\n");
|
||||
Console.WriteLine("\r\n[*] Action: Machine DPAPI Credential, Vault, and Certificate Triage\r\n");
|
||||
arguments.Remove("triage");
|
||||
|
||||
Dictionary<string, string> mappings = Triage.TriageSystemMasterKeys();
|
||||
|
||||
Triage.TriageSystemCreds(mappings);
|
||||
Triage.TriageSystemVaults(mappings);
|
||||
if (!Helpers.IsHighIntegrity())
|
||||
{
|
||||
Console.WriteLine("[X] Must be elevated to triage SYSTEM DPAPI Credentials!");
|
||||
}
|
||||
else
|
||||
{
|
||||
Dictionary<string, string> mappings = Triage.TriageSystemMasterKeys();
|
||||
|
||||
Console.WriteLine("\r\n[*] SYSTEM master key cache:\r\n");
|
||||
foreach (KeyValuePair<string, string> kvp in mappings)
|
||||
{
|
||||
Console.WriteLine("{0}:{1}", kvp.Key, kvp.Value);
|
||||
}
|
||||
Console.WriteLine();
|
||||
|
||||
Triage.TriageSystemCreds(mappings);
|
||||
Triage.TriageSystemVaults(mappings);
|
||||
Triage.TriageSystemCerts(mappings);
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -61,6 +61,7 @@ namespace SharpDPAPI.Commands
|
||||
{
|
||||
Triage.TriageUserCreds(masterkeys, server);
|
||||
Triage.TriageUserVaults(masterkeys, server);
|
||||
Triage.TriageUserCerts(masterkeys, server);
|
||||
Console.WriteLine();
|
||||
if (masterkeys.Count == 0)
|
||||
{
|
||||
|
||||
@@ -27,6 +27,7 @@ Machine/SYSTEM Triage:
|
||||
machinemasterkeys - triage all reachable machine masterkey files (elevates to SYSTEM to retrieve the DPAPI_SYSTEM LSA secret)
|
||||
machinecredentials - use 'machinemasterkeys' and then triage machine Credential files
|
||||
machinevaults - use 'machinemasterkeys' and then triage machine Vaults
|
||||
machinecerts - use 'machinemasterkeys' and then triage machine certificate stores
|
||||
machinetriage - run the 'machinecredentials' and 'machinevaults' commands
|
||||
|
||||
|
||||
@@ -37,7 +38,7 @@ User Triage:
|
||||
SharpDPAPI masterkeys </pvk:BASE64... | /pvk:key.pvk>
|
||||
|
||||
|
||||
Arguments for the credentials|vaults|rdg|triage|blob|ps commands:
|
||||
Arguments for the certificates|credentials|vaults|rdg|triage|blob|ps commands:
|
||||
|
||||
Decryption:
|
||||
/unprotect - force use of CryptUnprotectData() for 'ps', 'rdg', or 'blob' commands
|
||||
|
||||
@@ -4,6 +4,6 @@ namespace SharpDPAPI
|
||||
{
|
||||
public static class Version
|
||||
{
|
||||
public static string version = "1.6.1";
|
||||
public static string version = "1.7.0";
|
||||
}
|
||||
}
|
||||
|
||||
@@ -62,8 +62,10 @@
|
||||
<ItemGroup>
|
||||
<Compile Include="Commands\Backupkey.cs" />
|
||||
<Compile Include="Commands\Blob.cs" />
|
||||
<Compile Include="Commands\Certificate.cs" />
|
||||
<Compile Include="Commands\Credentials.cs" />
|
||||
<Compile Include="Commands\ICommand.cs" />
|
||||
<Compile Include="Commands\MachineCertificates.cs" />
|
||||
<Compile Include="Commands\Masterkeys.cs" />
|
||||
<Compile Include="Commands\Machinecredentials.cs" />
|
||||
<Compile Include="Commands\Machinemasterkeys.cs" />
|
||||
@@ -79,6 +81,7 @@
|
||||
<Compile Include="Domain\Info.cs" />
|
||||
<Compile Include="Domain\Version.cs" />
|
||||
<Compile Include="lib\Backup.cs" />
|
||||
<Compile Include="lib\BigInteger.cs" />
|
||||
<Compile Include="lib\Crypto.cs" />
|
||||
<Compile Include="lib\Dpapi.cs" />
|
||||
<Compile Include="lib\Helpers.cs" />
|
||||
@@ -86,6 +89,7 @@
|
||||
<Compile Include="lib\LSADump.cs" />
|
||||
<Compile Include="lib\PBKDF2.cs" />
|
||||
<Compile Include="lib\Triage.cs" />
|
||||
<Compile Include="lib\Tuple.cs" />
|
||||
<Compile Include="Program.cs" />
|
||||
<Compile Include="Properties\AssemblyInfo.cs" />
|
||||
</ItemGroup>
|
||||
|
||||
@@ -1,25 +0,0 @@
|
||||
|
||||
Microsoft Visual Studio Solution File, Format Version 12.00
|
||||
# Visual Studio 15
|
||||
VisualStudioVersion = 15.0.28307.168
|
||||
MinimumVisualStudioVersion = 10.0.40219.1
|
||||
Project("{FAE04EC0-301F-11D3-BF4B-00C04F79EFBC}") = "SharpDPAPI", "SharpDPAPI.csproj", "{5F026C27-F8E6-4052-B231-8451C6A73838}"
|
||||
EndProject
|
||||
Global
|
||||
GlobalSection(SolutionConfigurationPlatforms) = preSolution
|
||||
Debug|Any CPU = Debug|Any CPU
|
||||
Release|Any CPU = Release|Any CPU
|
||||
EndGlobalSection
|
||||
GlobalSection(ProjectConfigurationPlatforms) = postSolution
|
||||
{5F026C27-F8E6-4052-B231-8451C6A73838}.Debug|Any CPU.ActiveCfg = Debug|Any CPU
|
||||
{5F026C27-F8E6-4052-B231-8451C6A73838}.Debug|Any CPU.Build.0 = Debug|Any CPU
|
||||
{5F026C27-F8E6-4052-B231-8451C6A73838}.Release|Any CPU.ActiveCfg = Release|Any CPU
|
||||
{5F026C27-F8E6-4052-B231-8451C6A73838}.Release|Any CPU.Build.0 = Release|Any CPU
|
||||
EndGlobalSection
|
||||
GlobalSection(SolutionProperties) = preSolution
|
||||
HideSolutionNode = FALSE
|
||||
EndGlobalSection
|
||||
GlobalSection(ExtensibilityGlobals) = postSolution
|
||||
SolutionGuid = {09F62083-4525-408F-BE92-6DE7AA2A22BD}
|
||||
EndGlobalSection
|
||||
EndGlobal
|
||||
@@ -117,6 +117,23 @@ namespace SharpDPAPI
|
||||
}
|
||||
}
|
||||
|
||||
if (!String.IsNullOrEmpty(password))
|
||||
{
|
||||
if (mappings.Count == 0)
|
||||
{
|
||||
Console.WriteLine("\n[!] No master keys decrypted!\r\n");
|
||||
}
|
||||
else
|
||||
{
|
||||
Console.WriteLine("\n[*] User master key cache:\r\n");
|
||||
foreach (KeyValuePair<string, string> kvp in mappings)
|
||||
{
|
||||
Console.WriteLine("{0}:{1}", kvp.Key, kvp.Value);
|
||||
}
|
||||
Console.WriteLine();
|
||||
}
|
||||
}
|
||||
|
||||
Console.WriteLine();
|
||||
return mappings;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user