Files
GhostPack-SharpDPAPI/SharpDPAPI/Commands/Machinecredentials.cs
T
HarmJ0y 6388040a92 1.2.0 release (Troopers edition ;)
-Added remote server support for user triage functions
-Added machine triage (machinemasterkeys, machinecredentials, machinevaults, machinetriage)
-Expanded Vault credential format to handle vault credential clear attributes
-Expanded machine vault/credential search locations
-Broke out commands/files into the same general structure as Rubeus

P.S. this release was a huge PITA, hopefully it's appreciated ;)

Much <3 to @gentilkiwi for his excellent examples, and @tifkin_ for inspiring this work!
2019-03-24 22:12:45 -07:00

34 lines
1.1 KiB
C#
Executable File

using System;
using System.Collections.Generic;
using System.IO;
namespace SharpDPAPI.Commands
{
public class Machinecredentials : ICommand
{
public static string CommandName => "machinecredentials";
public void Execute(Dictionary<string, string> arguments)
{
Console.WriteLine("\r\n[*] Action: Machine DPAPI Credential Triage\r\n");
if (!Helpers.IsHighIntegrity())
{
Console.WriteLine("[X] Must be elevated to triage SYSTEM DPAPI Credentials!");
}
else
{
Dictionary<string, string> mappings = Triage.TriageSystemMasterKeys();
Console.WriteLine("\r\n[*] SYSTEM master key cache:\r\n");
foreach (KeyValuePair<string, string> kvp in mappings)
{
Console.WriteLine("{0}:{1}", kvp.Key, kvp.Value);
}
Console.WriteLine();
Triage.TriageSystemCreds(mappings);
}
}
}
}