Commit Graph
19 Commits
Author SHA1 Message Date
NK 06397923d2 Flip EPT scanning to opt-in and remove dev examples from repo
EPT scanning (for VBS/Credential Guard VMs) is now disabled by default
and enabled with --ept, since the vast majority of VMs don't use VBS.
Previously it was enabled by default and disabled with --no-ept.

Also remove examples/ (dev-only test utilities) from tracking.
2026-03-17 23:24:03 +01:00
NK 6a52381e46 Update README.md
- Split Quick Start into basic and advanced sections
- Fix binary size: ~5 MB → ~3 MB in ESXi deploy section
- Update module architecture tree with all source files:
  disk/ (vmdk, vdi, qcow2, vhd, vhdx, raw), sam/ (hive, bootkey,
  hashes, lsa, cache, dpapi_masterkey, ntfs_fallback), paging/
  (translate, entry, filebacked), pe/, utils
2026-03-17 14:42:46 +01:00
NK 4afa6eec69 Update README.md
- Add DPAPI master key hashes (hashcat 15300/15900) to disk extraction list
- Document missing CLI options: -r/--recurse, --scan, --provider, --no-ept,
  -v/--verbose, --build, --format brief
- Add brief format to output formats table
- Add dissect.vmfs (Fox-IT) and vmfs-tools to acknowledgements
2026-03-17 14:18:13 +01:00
NK 90074c601a Update README.md 2026-03-17 12:23:09 +01:00
NK 55aa12199c Update README.md 2026-03-16 18:08:30 +01:00
NK 9c74207520 Expand VMFS-6 section with discovery, auto-scan, and internals
Detail the --vmfs-list device discovery with example output, single-VM
vs auto-scan extraction modes, NTFS partition filtering for batch mode,
and the on-disk resolution chain diagram.
2026-03-10 10:55:32 +01:00
NK 8ddbcd28c4 Update README with VMFS-6 raw parser and Hyper-V VMRS support
Add documentation for two major new features:
- VMFS-6 raw SCSI device parser that bypasses ESXi file locks on running VMs
- Native Hyper-V .vmrs saved state parser (reverse-engineered, no Microsoft DLL)
2026-03-10 10:53:45 +01:00
NK d616a62775 v1.0.0: major rewrite — minidump support, pre-Vista, verified offsets, carve mode
LSASS credential extraction:
- Minidump (.dmp) support: full MSV/Kerberos/DPAPI/WDigest/TsPkg/SSP/
  LiveSSP/CredMan/CloudAP extraction from LSASS minidumps
- Pre-Vista (WinXP/Win2003): 32-bit EPROCESS, PAE paging, DES-X-CBC/RC4
- Win11 24H2 (26100+): correct EPROCESS offsets, MSV LIST_64/LIST_65,
  Kerberos variant with shifted offsets
- All MSV/SSP/LiveSSP/CloudAP/CredMan/WDigest offsets verified against
  mimikatz C structs and pypykatz templates
- EPROCESS offsets verified against Vergilius Project (13 variants)
- AES-CFB-128 cipher for non-8-aligned LSASS blobs
- DPAPI extraction from dpapisrv.dll (Win10 19041+ moved g_MasterKeyCacheList)
- Adaptive MSV offset discovery with build-number-aware variant ordering
- MSV NT hash fix: validated variant tracking + DPAPI cross-check for
  human accounts (SHA1 validation only works for machine accounts)
- Kerberos: AES/DES/RC4 key extraction, kirbi/ccache export, ticket
  quality validation, false positive filtering
- CloudAP: PRT blob extraction, 7 patterns covering Win10 1507–Win11 24H2
- CredMan: correct 2-level navigation (SET_LIST→STARTER→entry)
- Garbage filtering: repeating pattern detection, structural score
  validation, unknown etype rejection

Architecture:
- Carve mode: two-level degraded extraction for truncated memory files
- sam/mod.rs split into 4 submodules (partition, ntfs_reader,
  disk_fallbacks, vmdk_scan)
- ProviderStatus enum replacing string-based status tracking
- Safe read helpers (utils.rs) replacing 86 try_into().unwrap() calls
- GovmemError renamed to VmkatzError across all 35 source files
- Named paging constants (PAGE_PHYS_MASK, LARGE_*_MASK)

Performance:
- TLB cache for page table translation (256-entry direct-mapped)
- QCOW2 L2 table caching (64 tables, amortized I/O)
- VMware region binary search (partition_point)
- Stack-allocated ASN.1 length encoding, IV entropy histogram
- Single-pass System process + EPT scanning
- memchr::memmem for pattern matching

Robustness:
- Minidump parser hardening (bounds checks, overflow protection)
- PE32 validation (machine type, section count, optional header size)
- Multiple pagefile support (PTE pagefile_number routing)
- VMware embedded memory support (.vmss/.vmsn without .vmem)
- EPT false positive prevention (reserved bits, PDPT validation)
- VMEM truncation detection with user warning

Testing:
- 8 automated tests (4 unit + 4 integration)
- Non-regression framework: compare.py + esxi_test.sh
- All credentials verified against pypykatz on 10+ minidumps

CLI:
- --all/-a: show empty sessions (hidden by default)
- --no-ept: skip EPT scanning
- --kirbi/--ccache: Kerberos ticket export
- Silent output modes: ntlm, hashcat, text summary
- Hex display for non-printable machine account passwords
2026-03-09 16:21:24 +01:00
NK 08e95e7a82 Bump version to 0.2.2 2026-02-25 11:31:49 +01:00
NK 384fdcf191 Add raw file input: vmkatz ntds.dit SYSTEM, vmkatz SAM SYSTEM [SECURITY]
Accept multiple positional arguments and auto-detect file types by magic
bytes (ESE 0xEFCDAB89, registry "regf", minidump "MDMP").

- Raw NTDS.dit + SYSTEM hive: extracts AD hashes without a disk image
- Raw SAM + SYSTEM [+ SECURITY]: extracts local hashes, LSA secrets,
  and cached domain credentials from exported registry hives
- Auto-detects which hive is SYSTEM (bootkey extraction), SAM, or
  SECURITY — argument order does not matter
- Helpful error messages for incomplete inputs (e.g. NTDS without SYSTEM)
- LSASS minidump detection with guidance to use pypykatz (parser planned)
- Full backward compatibility with existing single-file workflows
2026-02-25 10:54:08 +01:00
NK b988715864 Add colored output, blank hash detection, and fix LM hash display
- Add --color auto|always|never for colored terminal output (TTY auto-detect)
- Highlight usernames (bold), hashes (yellow), section headers (green),
  provider names (cyan), plaintext passwords (red), blank hashes (dim)
- Annotate well-known blank password hashes with (blank) in text mode
- Hide zero LM hashes in text mode (mimikatz convention: LM disabled)
- Output aad3b435b51404eeaad3b435b51404ee for zero LM in ntlm/csv modes
  (impacket pwdump convention for downstream tool compatibility)
- Add acknowledgements section for mimikatz, pypykatz, and impacket
2026-02-25 10:37:15 +01:00
NK def787cfc4 Add native NTDS.dit extraction with ESE large page support
- Fix ESE parser for 32KB large pages (Win Server 2025): use 80-byte
  page header and 12-bit tag count for pages >=16KB
- Move NTDS code from src/sam/ to src/ntds/ module (ese.rs + mod.rs)
- Enable ntds.dit feature by default in Cargo.toml
- Fix conditional compilation warnings across all feature combinations
- Add test examples for ESE parser and end-to-end NTDS extraction
- Update README with NTDS usage, examples, and test results

Verified against 4 domain controllers:
  - 3x Win Server 2019 (8KB pages, GOAD lab): 18/19/15 hashes
  - 1x Win Server 2025 (32KB pages): 8 hashes
All hashes match impacket-secretsdump (which itself fails on 32KB pages).
2026-02-25 10:02:01 +01:00
NK a5d5b9a875 Add Proxmox Win11 test result to README 2026-02-24 23:03:41 +01:00
NK b241b4e805 Fix DCC2 key offset, GMSA display, and add block device support
- Fix DCC2 cached credentials: use NL$KM[0:16] as AES key instead of
  [16:32]. The secret is already stripped of its LSA_SECRET_BLOB header,
  so [16:32] was a double offset producing garbage decryption.
- Fix GMSA secrets: display managed service account passwords as hex
  instead of trying to decode binary data as UTF-16LE.
- Add raw block device support for LVM thin volumes (/dev/pve/...).
  Auto-detect block devices and route to SAM extraction. Use seek-to-end
  for device size since metadata().len() returns 0 for block devices.
- Update README with Proxmox LVM test results and Server 2025 support.
2026-02-24 23:02:12 +01:00
NK 396817c594 Add Clippy CI workflow and badge 2026-02-19 21:40:31 +01:00
NK 9a08d27c2f Replace static Rust badge with CI build status badge 2026-02-19 21:38:16 +01:00
NK 63d1e1404b Add MIT license, multi-platform CI, and README badges 2026-02-19 21:23:50 +01:00
NK 5e941b3ce3 Update gitignore and README 2026-02-19 21:11:30 +01:00
NK 0cd17ad6d9 Refactor credential extraction pipeline and add README 2026-02-19 19:49:13 +01:00