EPT scanning (for VBS/Credential Guard VMs) is now disabled by default
and enabled with --ept, since the vast majority of VMs don't use VBS.
Previously it was enabled by default and disabled with --no-ept.
Also remove examples/ (dev-only test utilities) from tracking.
Detail the --vmfs-list device discovery with example output, single-VM
vs auto-scan extraction modes, NTFS partition filtering for batch mode,
and the on-disk resolution chain diagram.
Add documentation for two major new features:
- VMFS-6 raw SCSI device parser that bypasses ESXi file locks on running VMs
- Native Hyper-V .vmrs saved state parser (reverse-engineered, no Microsoft DLL)
Accept multiple positional arguments and auto-detect file types by magic
bytes (ESE 0xEFCDAB89, registry "regf", minidump "MDMP").
- Raw NTDS.dit + SYSTEM hive: extracts AD hashes without a disk image
- Raw SAM + SYSTEM [+ SECURITY]: extracts local hashes, LSA secrets,
and cached domain credentials from exported registry hives
- Auto-detects which hive is SYSTEM (bootkey extraction), SAM, or
SECURITY — argument order does not matter
- Helpful error messages for incomplete inputs (e.g. NTDS without SYSTEM)
- LSASS minidump detection with guidance to use pypykatz (parser planned)
- Full backward compatibility with existing single-file workflows
- Fix ESE parser for 32KB large pages (Win Server 2025): use 80-byte
page header and 12-bit tag count for pages >=16KB
- Move NTDS code from src/sam/ to src/ntds/ module (ese.rs + mod.rs)
- Enable ntds.dit feature by default in Cargo.toml
- Fix conditional compilation warnings across all feature combinations
- Add test examples for ESE parser and end-to-end NTDS extraction
- Update README with NTDS usage, examples, and test results
Verified against 4 domain controllers:
- 3x Win Server 2019 (8KB pages, GOAD lab): 18/19/15 hashes
- 1x Win Server 2025 (32KB pages): 8 hashes
All hashes match impacket-secretsdump (which itself fails on 32KB pages).
- Fix DCC2 cached credentials: use NL$KM[0:16] as AES key instead of
[16:32]. The secret is already stripped of its LSA_SECRET_BLOB header,
so [16:32] was a double offset producing garbage decryption.
- Fix GMSA secrets: display managed service account passwords as hex
instead of trying to decode binary data as UTF-16LE.
- Add raw block device support for LVM thin volumes (/dev/pve/...).
Auto-detect block devices and route to SAM extraction. Use seek-to-end
for device size since metadata().len() returns 0 for block devices.
- Update README with Proxmox LVM test results and Server 2025 support.