Commit Graph
10 Commits
Author SHA1 Message Date
harmj0y ea8abe46f2 Version 1.7.0
-Landed @leftp's PR for user and machine certificate private key extraction
-Added cert triage to the "triage" and "machinetriage" commands
-Using /password:X now causes the DPAPI masterkey cache to be output
2020-05-06 12:29:35 -07:00
Eleftherios Panos 4fbe9a1eed Support for decrypting dpapi encrypted certificates 2020-05-02 14:44:46 +03:00
harmj0y 4662551256 Version 1.6.1
-Combined TriageUserMasterKeysWithPass into TriageUserMasterKeys
-'/password:X' now properly works in SharpDPAPI while elevated, as well as remotely
-'/password:X' now works for SharpChrome, elevated + remotely
2020-03-29 16:50:04 -07:00
harmj0y 3e95f5b37b Version 1.6.0
-Integrated new Chrome (v80+) AES statekey decryption from @djhohnstein's SharpChrome project.
-landed/expanded @lefterispan's PR that incorporates plaintext password masterkey decryption.
2020-03-27 15:03:09 -07:00
epan 351b73a941 Added support for decryption of masterkeys with user password 2020-03-26 13:53:09 +02:00
HarmJ0y c8563d31a6 Version 1.5.0
-Added *ps* command to decrypt exported PSCredential .xmls (thanks for the idea @gentilkiwi ;)
-Added README section for the *blob* command
-Misc. small output tweaks
2019-07-25 13:37:36 -07:00
HarmJ0y 9429ac19ba Version 1.4.0 - SharpChrome update
See CHANGELOG for complete change details and README for usage.
2019-05-22 22:19:47 -07:00
HarmJ0y 800a4a1ecc Version 1.3.1
-When using /server:X, .RDG files parsed from RDCMan.settings files are translated to UNC paths for parsing
-triage command when used against a remote /server:X now works properly
2019-05-09 18:56:43 -07:00
HarmJ0y 88ea5f6dc5 1.3.0 Release
-Added **blob** function to describe a raw DPAPI blob
-Added **rdg** function to triage RDCMan.settings/.RDG files and decrypt any saved RDP passwords
-Added IsTextUnicode() for vault/credential/blob decryption display, showing hex if unicode is detected
-Added /target:C:\FOLDER\ option for the **masterkeys** function, for offline masterkey decryption
-Updated README
2019-05-09 12:27:44 -07:00
HarmJ0y 6388040a92 1.2.0 release (Troopers edition ;)
-Added remote server support for user triage functions
-Added machine triage (machinemasterkeys, machinecredentials, machinevaults, machinetriage)
-Expanded Vault credential format to handle vault credential clear attributes
-Expanded machine vault/credential search locations
-Broke out commands/files into the same general structure as Rubeus

P.S. this release was a huge PITA, hopefully it's appreciated ;)

Much <3 to @gentilkiwi for his excellent examples, and @tifkin_ for inspiring this work!
2019-03-24 22:12:45 -07:00