mirror of
https://github.com/GhostPack/SharpDPAPI
synced 2026-06-08 11:11:23 +00:00
Version 1.8.0
Added the "search" command to search for DPAPI blobs Removed certificate triage from the machinetriage/triage commands Code cleanup and some refactoring
This commit is contained in:
@@ -5,6 +5,20 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/),
|
||||
and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
|
||||
|
||||
|
||||
## [1.8.0] - 2020-07-13
|
||||
|
||||
### Added
|
||||
* **SharpDPAPI** project
|
||||
* Landed @leechristensen's `search` command to search for DPAPI blobs
|
||||
|
||||
### Removed
|
||||
* **SharpDPAPI** project
|
||||
* Removed machine/user certificate triage from the `triage` and `machinetriage` commands
|
||||
|
||||
### Changed
|
||||
* Code cleanup and refactoring
|
||||
|
||||
|
||||
## [1.7.0] - 2020-05-06
|
||||
|
||||
### Added
|
||||
|
||||
@@ -31,7 +31,7 @@ namespace SharpDPAPI.Commands
|
||||
|
||||
Triage.TriageSystemCreds(mappings);
|
||||
Triage.TriageSystemVaults(mappings);
|
||||
Triage.TriageSystemCerts(mappings);
|
||||
//Triage.TriageSystemCerts(mappings);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -61,7 +61,7 @@ namespace SharpDPAPI.Commands
|
||||
{
|
||||
Triage.TriageUserCreds(masterkeys, server);
|
||||
Triage.TriageUserVaults(masterkeys, server);
|
||||
Triage.TriageUserCerts(masterkeys, server);
|
||||
// Triage.TriageUserCerts(masterkeys, server);
|
||||
Console.WriteLine();
|
||||
if (masterkeys.Count == 0)
|
||||
{
|
||||
|
||||
@@ -22,12 +22,20 @@ Retrieve a domain controller's DPAPI backup key, optionally specifying a DC and
|
||||
SharpDPAPI backupkey [/server:SERVER.domain] [/file:key.pvk]
|
||||
|
||||
|
||||
The *search* comand will search for potential DPAPI blobs in the registry, files, folders, and base64 blobs:
|
||||
|
||||
search /type:registry [/path:HKLM\path\to\key] [/showErrors]
|
||||
search /type:folder /path:C:\path\to\folder [/maxBytes:<numOfBytes>] [/showErrors]
|
||||
search /type:file /path:C:\path\to\file [/maxBytes:<numOfBytes>]
|
||||
search /type:base64 [/base:<base64 string>]
|
||||
|
||||
|
||||
Machine/SYSTEM Triage:
|
||||
|
||||
machinemasterkeys - triage all reachable machine masterkey files (elevates to SYSTEM to retrieve the DPAPI_SYSTEM LSA secret)
|
||||
machinecredentials - use 'machinemasterkeys' and then triage machine Credential files
|
||||
machinevaults - use 'machinemasterkeys' and then triage machine Vaults
|
||||
machinecerts - use 'machinemasterkeys' and then triage machine certificate stores
|
||||
machinecerts - use 'machinemasterkeys' and then triage machine certificate stores
|
||||
machinetriage - run the 'machinecredentials' and 'machinevaults' commands
|
||||
|
||||
|
||||
|
||||
@@ -4,6 +4,6 @@ namespace SharpDPAPI
|
||||
{
|
||||
public static class Version
|
||||
{
|
||||
public static string version = "1.7.0";
|
||||
public static string version = "1.8.0";
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user