Version 1.8.0

Added the "search" command to search for DPAPI blobs
Removed certificate triage from the machinetriage/triage commands
Code cleanup and some refactoring
This commit is contained in:
harmj0y
2020-07-13 10:52:45 -07:00
parent 5480219a46
commit f47dacdcb3
5 changed files with 26 additions and 4 deletions
+14
View File
@@ -5,6 +5,20 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/),
and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
## [1.8.0] - 2020-07-13
### Added
* **SharpDPAPI** project
* Landed @leechristensen's `search` command to search for DPAPI blobs
### Removed
* **SharpDPAPI** project
* Removed machine/user certificate triage from the `triage` and `machinetriage` commands
### Changed
* Code cleanup and refactoring
## [1.7.0] - 2020-05-06
### Added
+1 -1
View File
@@ -31,7 +31,7 @@ namespace SharpDPAPI.Commands
Triage.TriageSystemCreds(mappings);
Triage.TriageSystemVaults(mappings);
Triage.TriageSystemCerts(mappings);
//Triage.TriageSystemCerts(mappings);
}
}
}
+1 -1
View File
@@ -61,7 +61,7 @@ namespace SharpDPAPI.Commands
{
Triage.TriageUserCreds(masterkeys, server);
Triage.TriageUserVaults(masterkeys, server);
Triage.TriageUserCerts(masterkeys, server);
// Triage.TriageUserCerts(masterkeys, server);
Console.WriteLine();
if (masterkeys.Count == 0)
{
+9 -1
View File
@@ -22,12 +22,20 @@ Retrieve a domain controller's DPAPI backup key, optionally specifying a DC and
SharpDPAPI backupkey [/server:SERVER.domain] [/file:key.pvk]
The *search* comand will search for potential DPAPI blobs in the registry, files, folders, and base64 blobs:
search /type:registry [/path:HKLM\path\to\key] [/showErrors]
search /type:folder /path:C:\path\to\folder [/maxBytes:<numOfBytes>] [/showErrors]
search /type:file /path:C:\path\to\file [/maxBytes:<numOfBytes>]
search /type:base64 [/base:<base64 string>]
Machine/SYSTEM Triage:
machinemasterkeys - triage all reachable machine masterkey files (elevates to SYSTEM to retrieve the DPAPI_SYSTEM LSA secret)
machinecredentials - use 'machinemasterkeys' and then triage machine Credential files
machinevaults - use 'machinemasterkeys' and then triage machine Vaults
machinecerts - use 'machinemasterkeys' and then triage machine certificate stores
machinecerts - use 'machinemasterkeys' and then triage machine certificate stores
machinetriage - run the 'machinecredentials' and 'machinevaults' commands
+1 -1
View File
@@ -4,6 +4,6 @@ namespace SharpDPAPI
{
public static class Version
{
public static string version = "1.7.0";
public static string version = "1.8.0";
}
}