Commit Graph
51 Commits
Author SHA1 Message Date
Kiblyn11 df4f8836d5 doc and cleanup 2023-03-28 23:55:36 +02:00
Kiblyn11 dffd58325a Cleanup 2023-03-24 18:37:32 +01:00
unknown 578fe6e35d Add /rpc flag to allow users to resquest domain controller to decrypt masterkeys in a domain 2023-03-24 18:22:26 +01:00
Will f75ab5af85 Backupkey now not line wrapped
Backupkey now not line wrapped
2022-12-22 11:58:22 -08:00
Will 2677293c9b Merge pull request #19 from rxwx/master
Some masterkey features/improvements
2022-12-09 01:54:47 -08:00
Lee Christensen 7ff2537873 support additional string types + code cleanup 2022-11-17 03:28:33 -08:00
guervild 3322dbfee1 Fixed regex
Signed-off-by: guervild <11190755+guervild@users.noreply.github.com>
2022-11-16 23:51:19 +01:00
rxwx 4ffd2bd7ec * Added option to dump masterkey hashes in john/hashcat format.
* Added parsing of Preferred file to highlight current master key(s)
* Added auto extraction of SID using BK file or path when /server is specified
2022-10-31 10:50:40 +00:00
rxwx a88f7acdca Fixed bug in SID extraction. This should probably be moved to its own function that also tries to extract from the BK file 2022-10-31 09:05:44 +00:00
rxwx a81caa2052 Add support for specifying passwords in NTLM format 2022-10-31 08:31:23 +00:00
rxwx 7485244de7 Add HMAC validation to 3DES SHA1 2022-10-31 08:25:55 +00:00
guervild 0d1e17ed7c Add method to parse object data for sccm creds 2022-09-03 21:59:08 +02:00
Duane Michael 1afc55061d Significantly cleaned up SCCM output. 2022-07-13 10:25:21 -06:00
Duane Michael 67cc5f793f Modified sccm output 2022-07-13 09:49:00 -06:00
Duane Michael ffcfc126d9 Added SCCM to machinetriage 2022-07-11 16:31:46 -06:00
Duane Michael e7619df4fd Adjusted SCCM output 2022-07-11 16:30:59 -06:00
harmj0y 9df99d44f5 Version 1.11.3
-Added ability to use "/password" with "/target" for masterkey command
-Small update to README
2022-06-06 14:02:46 -07:00
harmj0y 81e1fcdd44 Additional error handling for SCCM command
Additional error handling for SCCM command
2022-05-17 11:14:16 -07:00
Duane Michael e836a83439 Fixing 2022-05-16 23:49:13 -06:00
Duane Michael d3d0505c47 Added SCCM command which includes functionality to retrieve NAA blobs via WMI and decrypt using system master keys. 2022-05-16 23:41:21 -06:00
harmj0y db6cb27aa3 Updated new Chrome cookie file locations
-Updated new Chrome cookie file locations
2022-01-12 17:08:07 -08:00
harmj0y a81031fe71 Version 1.11.1
-Default elevated SharpChrome triage behavior is to triage the current user unless additional masterkey material is supplied
-/target:X can now be a user folder
-Bug fixes
2021-03-05 09:55:28 -08:00
harmj0y 8730c3d670 Version 1.11.0
-Added "keepass" command
-Added "/entropy" flag to "blob" command
-Fix null byte bug
2021-03-01 13:55:21 -08:00
harmj0y 4425d8a595 Version 1.10.0
-CNG certificate private key support
-/nowrap added to `backupkey`
-key component error fix
-combined `machinecerts` to `certificates /machine`
-fixed SHA1 "hash" calculation for entropy
-only decrypted certs now display by default, `/showall` will show all
2021-02-25 10:37:37 -08:00
harmj0y 408e98ecd3 Version 1.9.2
-User certificate extraction corrected
-Added more certificate information on extraction (including Enhanced Key Usages)
-Fixed a few formatting issues
-Added /target option for machinecertificates command
2021-01-04 18:24:56 -08:00
harmj0y cfed81d01f Added /target support for 'masterkeys'
-Added ability to manually decrypt a target masterkey file/folder
2020-11-05 09:21:40 -08:00
harmj0y 5964eebc3e Version 1.9.0
Added Chromium-based Edge support for SharpChrome
Added /consoleoutfile support for SharpDPAPI/SharpChrome
Added "statekeys" command to SharpChrome
Fixed SharpChrome cookie bug for expires times of 0
2020-09-02 14:14:09 -07:00
harmj0y f47dacdcb3 Version 1.8.0
Added the "search" command to search for DPAPI blobs
Removed certificate triage from the machinetriage/triage commands
Code cleanup and some refactoring
2020-07-13 10:52:45 -07:00
leechristensen d85391a2c6 update text/readme 2020-07-04 19:25:08 -07:00
leechristensen 8a28e1a5ee fixed file enumeration bug 2020-07-04 19:22:36 -07:00
leechristensen 4263c024df Adding the search command 2020-07-04 17:29:54 -07:00
leechristensen 8ed8953f2b Adding the search command 2020-07-04 17:29:35 -07:00
leechristensen 563651494d more cleanups 2020-07-01 19:22:18 -07:00
leechristensen 06c6283169 code cleanup and refactoring 2020-07-01 19:18:11 -07:00
harmj0y ea8abe46f2 Version 1.7.0
-Landed @leftp's PR for user and machine certificate private key extraction
-Added cert triage to the "triage" and "machinetriage" commands
-Using /password:X now causes the DPAPI masterkey cache to be output
2020-05-06 12:29:35 -07:00
Eleftherios Panos 4fbe9a1eed Support for decrypting dpapi encrypted certificates 2020-05-02 14:44:46 +03:00
harmj0y 4662551256 Version 1.6.1
-Combined TriageUserMasterKeysWithPass into TriageUserMasterKeys
-'/password:X' now properly works in SharpDPAPI while elevated, as well as remotely
-'/password:X' now works for SharpChrome, elevated + remotely
2020-03-29 16:50:04 -07:00
harmj0y 3e95f5b37b Version 1.6.0
-Integrated new Chrome (v80+) AES statekey decryption from @djhohnstein's SharpChrome project.
-landed/expanded @lefterispan's PR that incorporates plaintext password masterkey decryption.
2020-03-27 15:03:09 -07:00
epan 351b73a941 Added support for decryption of masterkeys with user password 2020-03-26 13:53:09 +02:00
harmj0y f530523981 Version 1.5.1
-Timestamp parsing fix
-Added /setneverexpire flag for json cookie output
-misc small output tweaks
2019-12-18 12:04:31 -08:00
HarmJ0y c8563d31a6 Version 1.5.0
-Added *ps* command to decrypt exported PSCredential .xmls (thanks for the idea @gentilkiwi ;)
-Added README section for the *blob* command
-Misc. small output tweaks
2019-07-25 13:37:36 -07:00
HarmJ0y d597b546d6 machinetriage bug fix 2019-06-12 21:03:56 -04:00
HarmJ0y 9429ac19ba Version 1.4.0 - SharpChrome update
See CHANGELOG for complete change details and README for usage.
2019-05-22 22:19:47 -07:00
HarmJ0y 800a4a1ecc Version 1.3.1
-When using /server:X, .RDG files parsed from RDCMan.settings files are translated to UNC paths for parsing
-triage command when used against a remote /server:X now works properly
2019-05-09 18:56:43 -07:00
HarmJ0y 88ea5f6dc5 1.3.0 Release
-Added **blob** function to describe a raw DPAPI blob
-Added **rdg** function to triage RDCMan.settings/.RDG files and decrypt any saved RDP passwords
-Added IsTextUnicode() for vault/credential/blob decryption display, showing hex if unicode is detected
-Added /target:C:\FOLDER\ option for the **masterkeys** function, for offline masterkey decryption
-Updated README
2019-05-09 12:27:44 -07:00
HarmJ0y b0663b4ccd -README clarifications
-Added HMAC verification to MasterKey decryption with sha hashes
2019-03-26 22:17:57 -04:00
HarmJ0y 6388040a92 1.2.0 release (Troopers edition ;)
-Added remote server support for user triage functions
-Added machine triage (machinemasterkeys, machinecredentials, machinevaults, machinetriage)
-Expanded Vault credential format to handle vault credential clear attributes
-Expanded machine vault/credential search locations
-Broke out commands/files into the same general structure as Rubeus

P.S. this release was a huge PITA, hopefully it's appreciated ;)

Much <3 to @gentilkiwi for his excellent examples, and @tifkin_ for inspiring this work!
2019-03-24 22:12:45 -07:00
HarmJ0y d819e3c527 Version 1.1.1 release
Fixed Policy.vpol parsing
Integrated @leechristensen's aggressor script
2019-03-15 16:55:06 -07:00
Lee Christensen 90ff5b4104 Added aggressor script, add try/catch in main() 2019-03-15 13:59:24 -07:00
HarmJ0y c3a8a15d6c Version 1.1.0 release.
See CHANGELOG for details.
2019-03-15 01:36:12 -07:00