mirror of
https://github.com/GhostPack/SharpDPAPI
synced 2026-06-08 11:11:23 +00:00
-Added remote server support for user triage functions -Added machine triage (machinemasterkeys, machinecredentials, machinevaults, machinetriage) -Expanded Vault credential format to handle vault credential clear attributes -Expanded machine vault/credential search locations -Broke out commands/files into the same general structure as Rubeus P.S. this release was a huge PITA, hopefully it's appreciated ;) Much <3 to @gentilkiwi for his excellent examples, and @tifkin_ for inspiring this work!
34 lines
1.1 KiB
C#
Executable File
34 lines
1.1 KiB
C#
Executable File
using System;
|
|
using System.Collections.Generic;
|
|
using System.IO;
|
|
|
|
namespace SharpDPAPI.Commands
|
|
{
|
|
public class Machinecredentials : ICommand
|
|
{
|
|
public static string CommandName => "machinecredentials";
|
|
|
|
public void Execute(Dictionary<string, string> arguments)
|
|
{
|
|
Console.WriteLine("\r\n[*] Action: Machine DPAPI Credential Triage\r\n");
|
|
|
|
if (!Helpers.IsHighIntegrity())
|
|
{
|
|
Console.WriteLine("[X] Must be elevated to triage SYSTEM DPAPI Credentials!");
|
|
}
|
|
else
|
|
{
|
|
Dictionary<string, string> mappings = Triage.TriageSystemMasterKeys();
|
|
|
|
Console.WriteLine("\r\n[*] SYSTEM master key cache:\r\n");
|
|
foreach (KeyValuePair<string, string> kvp in mappings)
|
|
{
|
|
Console.WriteLine("{0}:{1}", kvp.Key, kvp.Value);
|
|
}
|
|
Console.WriteLine();
|
|
|
|
Triage.TriageSystemCreds(mappings);
|
|
}
|
|
}
|
|
}
|
|
} |