Commit Graph
92 Commits
Author SHA1 Message Date
NK 49a3991faa Detect BitLocker-encrypted partitions and warn the user
Check for the -FVE-FS- OEM ID in partition boot records before
attempting NTFS parsing. When BitLocker is detected, skip the
partition and display a clear error message instead of failing
silently with "No registry hives found".

Applied to SAM extraction, LSA secrets, and NTDS.dit extraction paths.
2026-03-20 21:33:51 +01:00
NK febbb0e4d9 Fix embedded .vmsn memory and hide machine account passwords
VMware layer:
- Fix base_offset not set when .vmsn has region tags but no separate
  .vmem file (embedded memory). Reads were at wrong file offset.
- Tested on ESXi 6.7 with Win Server 2016 embedded .vmsn snapshot.

Display:
- Don't display Kerberos/WDigest passwords for machine accounts (username
  ending with $) — they are binary blobs, not useful plaintext. The
  Kerberos keys (AES256, RC4=NT hash) are the exploitable forms.
- Don't count machine passwords in the summary line.
- Truncate long hex passwords to "(hex, N bytes) first32bytes..." when
  displayed for other non-printable passwords.
2026-03-20 21:27:51 +01:00
NK abb72761ab Add QEMU/KVM/Proxmox savevm state parser and improve System process discovery
New parser (src/qemu/savevm.rs):
- Parse QEVM magic, RAM block list, and page entries (PAGE/ZERO)
- MMIO gap remapping for q35+UEFI (below_4g=0x80000000)
- Skip non-RAM device sections (dirty-bitmap, etc.) via forward scanning
- HashMap-based deduplication for dirty page iterations (last-write-wins)
- Auto-detection via QEVM magic in format dispatcher

System process discovery improvements:
- Validate candidates by translating Flink VA to physical and checking the
  linked EPROCESS has a printable ImageFileName and valid kernel-mode Flink
- Rejects stale EPROCESS remnants with corrupted page tables

Tested on Proxmox VMs: DC25 (Win Server 2025, 4GB) and WKS11 (Win11, 8GB)
2026-03-20 19:28:54 +01:00
NK 552d444cfe Unify Kerberos credential extraction for x64/x86
- Merge 8 duplicated _x86 functions into single arch-aware implementations:
  walk_avl_tree, read_kerb_external_name, extract_kerb_password,
  extract_tickets_from_list, extract_single_ticket, detect_kerb_offsets,
  extract_kerb_keys, extract_kerberos_credentials
- All structure offsets computed from arch.ptr_size() and arch.ustr_size()
- Delete extract_kerberos_credentials_arch wrapper and all _x86 variants
- Net reduction: -580 lines
2026-03-20 19:27:19 +01:00
NK 649976e96a Unify MSV session and credential extraction for x64/x86
- Merge extract_msv_sessions_arch and extract_msv_credentials_arch into the
  main functions, selecting offset variants by arch at runtime
- Make all walkers arch-aware: walk_session_buckets, walk_session_list,
  walk_msv_list, walk_hash_table, find_inline_hash_table,
  find_credentials_ptr_in_entry
- Delete 258 lines of duplicated x86 code (extract_msv_sessions_arch,
  extract_msv_credentials_arch, try_extract_primary_cred_x86)
- x86 now gets scoring, enrichment, multi-pass credential scanning, and
  SHA1 validation — previously x64-only features
- Add variant_order_for_build_arch for x86 build-aware variant ordering
2026-03-20 19:26:55 +01:00
NK b0c8bcae49 Refactor LSASS providers: extract shared helpers and unify x64/x86 code paths
- Add read_ptr_from_buf, walk_list, read_data_section, scan_data_for_list_head
  to types.rs, eliminating ~200 lines of duplicated boilerplate across providers
- Unify kerberos.rs: merge 8 duplicated _x86 functions into arch-aware versions
  (walk_avl_tree, extract_single_ticket, read_kerb_external_name, etc.), -440 lines
- Fix CloudAP: read account name from toName_ptr (+0x58) instead of hashName (+0x68)
  which is a SHA hash, not the readable UPN. Add 3 offset variants (1507-1607,
  1703-1709, 1803+) with auto-detection. Remove useless hashName fallback.
- Fix walk_session_buckets using x64-only read_win_unicode_string and read_virt_u64
  for pointers — now uses arch-aware read_ustring and read_ptr
2026-03-20 19:26:30 +01:00
NK 35fc30e0a3 Add GitHub issue templates for bug reports and feature requests
Bug template requires: vmkatz version, input format, guest OS/arch,
host platform, filesystem, full command output, and file details.
Blank issues disabled to enforce structured reports.
2026-03-18 23:26:06 +01:00
NK 3706710552 Add x86 EPROCESS offsets for Vista/Win7/Win8/8.1 and fix Vista x86 classification
- Add EPROCESS offset tables for Vista SP2 x86, Win7 SP1 x86, Win8/8.1 x86
- Fix is_prevista_x86 threshold: Vista x86 (PID=0x9C) uses AES/3DES like
  Win7+, not DES-X/RC4. Tighten cutoff from 0xA0 to 0x98.
- Update README: 18 offset tables, correct x86 support status
2026-03-18 00:03:20 +01:00
NK e2c078d4f7 Bump version to 1.2.2 2026-03-17 23:27:00 +01:00
NK 06397923d2 Flip EPT scanning to opt-in and remove dev examples from repo
EPT scanning (for VBS/Credential Guard VMs) is now disabled by default
and enabled with --ept, since the vast majority of VMs don't use VBS.
Previously it was enabled by default and disabled with --no-ept.

Also remove examples/ (dev-only test utilities) from tracking.
2026-03-17 23:24:03 +01:00
NK 97d1d18c6f Support VBox 5.x-7.x PGM saved state versions in .sav parser
The PGM struct fields size varies by VirtualBox version:
- v14 (VBox 7.x): 78 bytes — existing behavior
- v12-13 (VBox 5.x-6.x): 74 bytes — no cBalloonedPages field
- v11 (VBox 4.1+): 70 bytes — pre-balloon support

Previously hardcoded to skip(78), which corrupted RAM extraction
for any .sav file not from VBox 7.x. Now reads the PGM unit
version from the unit header and adapts accordingly.
2026-03-17 23:16:40 +01:00
NK 6a52381e46 Update README.md
- Split Quick Start into basic and advanced sections
- Fix binary size: ~5 MB → ~3 MB in ESXi deploy section
- Update module architecture tree with all source files:
  disk/ (vmdk, vdi, qcow2, vhd, vhdx, raw), sam/ (hive, bootkey,
  hashes, lsa, cache, dpapi_masterkey, ntfs_fallback), paging/
  (translate, entry, filebacked), pe/, utils
2026-03-17 14:42:46 +01:00
NK 4afa6eec69 Update README.md
- Add DPAPI master key hashes (hashcat 15300/15900) to disk extraction list
- Document missing CLI options: -r/--recurse, --scan, --provider, --no-ept,
  -v/--verbose, --build, --format brief
- Add brief format to output formats table
- Add dissect.vmfs (Fox-IT) and vmfs-tools to acknowledgements
2026-03-17 14:18:13 +01:00
NK 90074c601a Update README.md 2026-03-17 12:23:09 +01:00
NK 2f01b48258 Validate GPT entry size before allocation and slice access
Reject entry_size outside 128-4096 range to prevent:
- panic on slice &entry[0..16] when entry_size < 16
- OOM allocation from forged u32 entry_size
GPT spec mandates minimum 128 bytes per partition entry.
2026-03-17 02:16:51 +01:00
NK a1e0a65e7f Fix VDI parent resolution and coalesce_pages overflow
- VDI: search for location= attribute AFTER the UUID match, not in a
  window that extends 200 bytes before it. Prevents picking a location
  from a different HardDisk entry in multi-disk .vbox files.
- dump: use saturating_add/sub in coalesce_pages to prevent u64
  overflow on kernel addresses near 0xFFFFFFFFFFFFF000.
2026-03-17 01:52:05 +01:00
NK 75b2351363 Fix cfg gate on fmt_lm_pwdump: sam feature, not ntds.dit
The function is used by both SAM and NTDS output paths. Gating it on
ntds.dit broke compilation when sam was enabled without ntds.dit
(e.g. --features sam or --features vmfs).
2026-03-17 01:48:26 +01:00
NK 09dae5b16c Cap QCOW2 L1 table allocation and fix VMware tag parsing
- QCOW2: cap l1_table pre-allocation to 1M entries to prevent OOM
  from forged l1_size in header (actual entries read from file)
- VMware tags: validate all index bytes are available before parsing,
  break out of tag loop instead of producing truncated indices
2026-03-17 01:41:56 +01:00
NK 873c93357d Validate NTFS boot sector cluster_size and record_size
Reject zero values parsed from untrusted NTFS metadata to prevent
division-by-zero panics in cluster offset and MFT record calculations.
2026-03-17 01:40:05 +01:00
NK f99b1a4c74 Guard VMware parser against malformed .vmsn files
- Bounds-check tag_start before slicing vmsn_data (prevents panic on
  forged memory_group.offset beyond file size)
- Cap Vec::with_capacity for group_count based on actual data size
  (prevents OOM from forged u32 in header)
- Cap regions Vec::with_capacity to 4096 (prevents OOM from forged
  regionsCount tag value)
2026-03-17 01:33:35 +01:00
NK e538e27209 Harden SAM/ESE/VMFS parsers against malformed inputs
- SAM hashes: use saturating_add + checked_add for V-value offset
  calculations to prevent overflow on crafted hive data
- ESE: check tag_idx overflow in read_tag before subtraction from
  page_size (prevents wrap-around on large tag indices)
- ESE: explicit guard last_var_id < 128 in variable column parsing
  to prevent underflow in offset table size calculation
- VMFS flat VMDK: guard block_size == 0 in resolve_position and Read
  impl to prevent division by zero on corrupt superblock
2026-03-17 01:29:33 +01:00
NK f798f59224 Harden parsers against malformed inputs
- MSV: propagate arch parameter instead of hardcoding Arch::X64,
  fixes credential extraction on x86/WoW64 processes
- VMDK: validate grain_size != 0 and numGTEsPerGT != 0 (div-by-zero)
- VMDK: reject extent number 0 in parse_extent_number (underflow)
- VHDX: validate block_size and logical_sector_size != 0
- VHD: validate block_size != 0 in dynamic header
- VMFS: guard file_block_size, clusters_per_group, and
  parent_resources_per_group against zero (div-by-zero)
- QEMU ELF: use checked arithmetic for program header offsets
- VMware tags: bounds-check data_size before advancing parse position
- Process walk: guard flink_phys underflow in enumerate_processes
2026-03-17 01:22:11 +01:00
NK 1658606d1a Bump version to v1.2.1
- Fix SSP decryption: use AES-CFB-8 instead of CFB-128 (matches mimikatz)
- Fix machine account password display: raw hex instead of lossy UTF-16
- Truncate decrypted passwords to UNICODE_STRING.Length (drop padding)
2026-03-16 23:34:33 +01:00
NK 5115e632ef Fix lossy password decoding for machine accounts
- Truncate decrypted password to UNICODE_STRING.Length bytes (was using
  MaximumLength, including garbage padding after the actual data)
- Add decode_password_bytes: hex-encode raw bytes directly for binary
  passwords instead of round-tripping through lossy UTF-16LE decode
  (char::REPLACEMENT_CHARACTER destroyed original bytes)
- Apply to all providers via decrypt_unicode_string_password_arch and
  the SSP-specific CFB-8 variant
- Update CSV/text output to use raw hex for binary passwords
2026-03-16 23:28:18 +01:00
NK 5f24e8f528 Add missing vmrs.rs module 2026-03-16 23:02:10 +01:00
NK dab403c139 Bump version to v1.2.0
- Fix SSP decryption: use AES-CFB-8 (8-bit segments) instead of CFB-128.
  SSP is the only LSASS provider using CFB-8 (mimikatz: KP_MODE_BITS=8).
  Previously produced garbage output for SSP passwords.
- Fix .vmsn hang: mmap metadata instead of loading entire multi-GB file
- Reduce EPT scan budget (4GB cap, 1GB gap) for faster non-VBS bail-out
- Fix crash on ESXi: spawn 8MB stack thread (ESXi default is 512KB)
- Add credential deduplication: merge duplicate sessions by default (-a for all)
- Add version banner at startup
- Fix snapshot labels: recognize .vmss and .vmrs extensions
- Add Hyper-V VMRS saved state support
- Add Clone derives on credential types
2026-03-16 22:57:08 +01:00
NK 55aa12199c Update README.md 2026-03-16 18:08:30 +01:00
NK 9014a3f2ef Bump version to v1.1.1
- Fix .vmsn hang: use mmap instead of fs::read for metadata parsing,
  avoiding multi-GB allocation on embedded memory snapshots
- Reduce EPT scan budget (4GB cap, 1GB gap limit) for faster bail-out
  on non-VBS VMs (70s → 10s on 16GB snapshot)
2026-03-16 18:05:57 +01:00
NK f6001f8a0b Bump version to v1.1.0
New features: VMFS-6 raw SCSI parser, native Hyper-V VMRS parser.
2026-03-10 11:01:47 +01:00
NK 9c74207520 Expand VMFS-6 section with discovery, auto-scan, and internals
Detail the --vmfs-list device discovery with example output, single-VM
vs auto-scan extraction modes, NTFS partition filtering for batch mode,
and the on-disk resolution chain diagram.
2026-03-10 10:55:32 +01:00
NK 8ddbcd28c4 Update README with VMFS-6 raw parser and Hyper-V VMRS support
Add documentation for two major new features:
- VMFS-6 raw SCSI device parser that bypasses ESXi file locks on running VMs
- Native Hyper-V .vmrs saved state parser (reverse-engineered, no Microsoft DLL)
2026-03-10 10:53:45 +01:00
NK 6c35d9f242 Add VMFS feature flag, device enumeration, and fix all clippy warnings
VMFS module:
- Gate behind `vmfs` Cargo feature (included in defaults, depends on sam)
- Add --vmfs-list to discover VMFS-6 devices and flat VMDKs on ESXi
- Add --vmfs-device/--vmdk auto-scan with NTFS partition pre-check
- Fix label reading: use data_offset at LVM header 0x7A (not 0xC8)
- Filter out duplicate vml. symlink devices

Clippy fixes across all feature combinations:
- Remove unused fields, methods, constants in vmfs.rs
- Remove redundant `as u64` casts, use div_ceil()
- Gate MSSK_TAG and fmt_lm_pwdump behind their feature flags
- Simplify boolean expressions in ntfs_fallback.rs
- Suppress unit-type warnings for PagefileRef/DiskPathRef cfg stubs

Zero warnings on: --features vmware, all-except-vmfs, --all-features.
2026-03-10 03:01:13 +01:00
NK 2beb89a745 Add resilient I/O for reading live/in-use block devices
On Proxmox (and ESXi with VMFS), reading disk images of running VMs
can hit transient I/O errors on individual sectors/clusters that are
temporarily locked by the hypervisor.

Instead of aborting on the first read error, all NTFS and registry
hive reading paths now use block-level resilient I/O:
- read_from_data_runs: reads 4KB blocks individually, zero-fills
  blocks that fail, and continues to the next block
- resilient_read_blocks: MFT batch reads zero-fill failing records
  instead of skipping entire batches
- read_file_data (ntfs_reader): falls back to chunked 4KB reads
  when exact read fails
- Partition table parsing: skips unreadable GPT entries gracefully
- Hive scanning: skips unreadable chunks instead of aborting scan
- MFTMirr: accepts records without FILE signature check on first
  extent (live VMs may have transient I/O on header sectors)
- $ATTRIBUTE_LIST parsing for extension MFT records (large hives)

Tested on Proxmox with running Win11 and DC VMs — extracts SAM/SYSTEM
hives and NTDS.dit successfully despite scattered I/O errors.
2026-03-10 03:00:59 +01:00
NK 0a1febd8f0 Add VMFS-6 raw parser for direct ESXi SCSI device access
Self-contained VMFS-6 parser that reads flat VMDKs directly from raw
SCSI partition devices, bypassing VMFS file locks on running VMs.

Key features:
- Full VMFS-6 on-disk format parsing: LVM, superblock, FDC, SBC, PB/PB2
- Directory traversal with allocation map and entry bitmap support
- Block map building with batched PB reads (320 reads vs 262K individual)
- Sub-block resolution for small files via SBC resource metadata
- Auto-scan mode: enumerates all VMs, skips non-Windows VMDKs
- NTFS-only extraction for fast batch scanning

Verified on ESXi 8.0 datastore: 73 VMDKs scanned in <2min, 4 Windows
VMs with SAM hashes + LSA secrets + DCC2 cached credentials extracted.
2026-03-10 02:31:40 +01:00
NK a386bc19d5 build: replace env_logger with inline logger (3.0M → 2.3M)
env_logger pulled in regex + jiff (~700KB). Replace with a 10-line
SimpleLogger that writes to stderr. Same behavior, zero dependencies.
2026-03-09 16:53:27 +01:00
NK 85348ed84f build: optimize binary size (4.0M → 3.0M)
- Add opt-level = "z" to release profile (size-optimized codegen)
- Remove redundant strip/editbin steps from CI (strip = true in Cargo.toml
  already handles all targets)
- Remove redundant --features "ntds.dit" (already in default features)
2026-03-09 16:39:30 +01:00
NK d616a62775 v1.0.0: major rewrite — minidump support, pre-Vista, verified offsets, carve mode
LSASS credential extraction:
- Minidump (.dmp) support: full MSV/Kerberos/DPAPI/WDigest/TsPkg/SSP/
  LiveSSP/CredMan/CloudAP extraction from LSASS minidumps
- Pre-Vista (WinXP/Win2003): 32-bit EPROCESS, PAE paging, DES-X-CBC/RC4
- Win11 24H2 (26100+): correct EPROCESS offsets, MSV LIST_64/LIST_65,
  Kerberos variant with shifted offsets
- All MSV/SSP/LiveSSP/CloudAP/CredMan/WDigest offsets verified against
  mimikatz C structs and pypykatz templates
- EPROCESS offsets verified against Vergilius Project (13 variants)
- AES-CFB-128 cipher for non-8-aligned LSASS blobs
- DPAPI extraction from dpapisrv.dll (Win10 19041+ moved g_MasterKeyCacheList)
- Adaptive MSV offset discovery with build-number-aware variant ordering
- MSV NT hash fix: validated variant tracking + DPAPI cross-check for
  human accounts (SHA1 validation only works for machine accounts)
- Kerberos: AES/DES/RC4 key extraction, kirbi/ccache export, ticket
  quality validation, false positive filtering
- CloudAP: PRT blob extraction, 7 patterns covering Win10 1507–Win11 24H2
- CredMan: correct 2-level navigation (SET_LIST→STARTER→entry)
- Garbage filtering: repeating pattern detection, structural score
  validation, unknown etype rejection

Architecture:
- Carve mode: two-level degraded extraction for truncated memory files
- sam/mod.rs split into 4 submodules (partition, ntfs_reader,
  disk_fallbacks, vmdk_scan)
- ProviderStatus enum replacing string-based status tracking
- Safe read helpers (utils.rs) replacing 86 try_into().unwrap() calls
- GovmemError renamed to VmkatzError across all 35 source files
- Named paging constants (PAGE_PHYS_MASK, LARGE_*_MASK)

Performance:
- TLB cache for page table translation (256-entry direct-mapped)
- QCOW2 L2 table caching (64 tables, amortized I/O)
- VMware region binary search (partition_point)
- Stack-allocated ASN.1 length encoding, IV entropy histogram
- Single-pass System process + EPT scanning
- memchr::memmem for pattern matching

Robustness:
- Minidump parser hardening (bounds checks, overflow protection)
- PE32 validation (machine type, section count, optional header size)
- Multiple pagefile support (PTE pagefile_number routing)
- VMware embedded memory support (.vmss/.vmsn without .vmem)
- EPT false positive prevention (reserved bits, PDPT validation)
- VMEM truncation detection with user warning

Testing:
- 8 automated tests (4 unit + 4 integration)
- Non-regression framework: compare.py + esxi_test.sh
- All credentials verified against pypykatz on 10+ minidumps

CLI:
- --all/-a: show empty sessions (hidden by default)
- --no-ept: skip EPT scanning
- --kirbi/--ccache: Kerberos ticket export
- Silent output modes: ntlm, hashcat, text summary
- Hex display for non-printable machine account passwords
2026-03-09 16:21:24 +01:00
NK ac15c32d37 Fix MSV NT hash variant selection for human accounts
SHA1 cross-validation only works for machine accounts (where
ShaOwPassword = SHA1(NTHash)). For human accounts, ShaOwPassword =
SHA1(UTF16LE(password)), so the entropy fallback could pick the wrong
offset variant (reading DPAPI Protected field as NT hash).

Two fixes:
- Track SHA1-validated variant across credentials in same LSASS process
  (same Windows build → same offsets). Reuse for subsequent credentials.
- DPAPI cross-check: when isDPAPIProtected=1, reject entropy candidates
  whose NT hash matches the DPAPIProtected field at offset 0x6A.

Verified: Administrator NT hash now correct (09f6ff15...) on both
Citrix DC snapshots, matching pypykatz ground truth.
2026-02-26 12:18:37 +01:00
NK 0dd011dd49 Fix false positive tickets and improve MSV credential matching
- Validate Kerberos tickets: reject paged-out blobs (>75% zeros),
  garbage key_types (>0xFF), and all-zero timestamps
- Improve MSV physical scan LUID matching: match by username only
  when domain is empty or "." (local machine shorthand)
- Eliminates synthetic LUIDs and garbage ticket output
2026-02-26 04:24:55 +01:00
NK f2bd87d305 Add physical scan for Kerberos keys and fix credential matching
- Extract pKeyList keys even when credential substructure is paged out
- Physical scan for KIWI_KERBEROS_KEYS_LIST_6 structures in LSASS pages
- Match key groups to credentials via RC4 key = NT hash correlation
- Merge Kerberos credentials by username/domain when LUID is unknown
- Remove duplicate DPAPI line (was always same as SHA1)
- Hide all-zero LM hashes in output
2026-02-26 03:21:33 +01:00
NK 2700102ae9 Add --kirbi and --ccache flags for Kerberos ticket export
- --kirbi <DIR>: export individual .kirbi files per ticket
- --ccache <FILE>: export all tickets as MIT Kerberos ccache v4 format
- Uses actual Kerberos name types from ticket data for ccache principals
- Sanitizes filenames for cross-platform compatibility
2026-02-25 23:38:02 +01:00
NK 1dcda44efe Add Kerberos AES/DES/RC4 key extraction from pKeyList
Read KIWI_KERBEROS_KEYS_LIST_6 from the session entry's pKeyList
pointer, parse KERB_HASHPASSWORD_6[_1607] entries, decrypt and
extract AES128, AES256, RC4 (NTLM), and DES key material.

Offsets for Win10 1607+, Win10 1507, Win8, and Win7 variants.
Keys are displayed in both text and Display formats.

This closes the gap vs pypykatz which extracts these keys from
minidumps. VMkatz now extracts passwords, keys, and tickets.
2026-02-25 23:28:35 +01:00
NK 28afe24f98 Filter false positive LSASS sessions from garbage memory
Add LUID and username validation to reject phantom sessions caused by
wrong MSV struct offsets being applied to valid memory. Filters:
- LUID must have high 32 bits zero (real Windows LUIDs are 32-bit)
- Username must contain at least one alphanumeric char, no file paths
  or control characters

Tested on SilverFort-AD (Server 2022 DC, 32GB): eliminates 3 false
sessions while preserving all 10 legitimate ones.
2026-02-25 22:57:09 +01:00
NK 08e95e7a82 Bump version to 0.2.2 2026-02-25 11:31:49 +01:00
NK d262b7fad3 Fix clippy len_zero warning
Use !is_empty() instead of len() >= 1 for clearer intent.
2026-02-25 11:00:52 +01:00
NK e774c481b5 Bump version to 0.2.1 2026-02-25 10:56:04 +01:00
NK 384fdcf191 Add raw file input: vmkatz ntds.dit SYSTEM, vmkatz SAM SYSTEM [SECURITY]
Accept multiple positional arguments and auto-detect file types by magic
bytes (ESE 0xEFCDAB89, registry "regf", minidump "MDMP").

- Raw NTDS.dit + SYSTEM hive: extracts AD hashes without a disk image
- Raw SAM + SYSTEM [+ SECURITY]: extracts local hashes, LSA secrets,
  and cached domain credentials from exported registry hives
- Auto-detects which hive is SYSTEM (bootkey extraction), SAM, or
  SECURITY — argument order does not matter
- Helpful error messages for incomplete inputs (e.g. NTDS without SYSTEM)
- LSASS minidump detection with guidance to use pypykatz (parser planned)
- Full backward compatibility with existing single-file workflows
2026-02-25 10:54:08 +01:00
NK a794c19388 Bump version to 0.2.0 2026-02-25 10:42:16 +01:00
NK b988715864 Add colored output, blank hash detection, and fix LM hash display
- Add --color auto|always|never for colored terminal output (TTY auto-detect)
- Highlight usernames (bold), hashes (yellow), section headers (green),
  provider names (cyan), plaintext passwords (red), blank hashes (dim)
- Annotate well-known blank password hashes with (blank) in text mode
- Hide zero LM hashes in text mode (mimikatz convention: LM disabled)
- Output aad3b435b51404eeaad3b435b51404ee for zero LM in ntlm/csv modes
  (impacket pwdump convention for downstream tool compatibility)
- Add acknowledgements section for mimikatz, pypykatz, and impacket
2026-02-25 10:37:15 +01:00
NK def787cfc4 Add native NTDS.dit extraction with ESE large page support
- Fix ESE parser for 32KB large pages (Win Server 2025): use 80-byte
  page header and 12-bit tag count for pages >=16KB
- Move NTDS code from src/sam/ to src/ntds/ module (ese.rs + mod.rs)
- Enable ntds.dit feature by default in Cargo.toml
- Fix conditional compilation warnings across all feature combinations
- Add test examples for ESE parser and end-to-end NTDS extraction
- Update README with NTDS usage, examples, and test results

Verified against 4 domain controllers:
  - 3x Win Server 2019 (8KB pages, GOAD lab): 18/19/15 hashes
  - 1x Win Server 2025 (32KB pages): 8 hashes
All hashes match impacket-secretsdump (which itself fails on 32KB pages).
2026-02-25 10:02:01 +01:00
NK a5d5b9a875 Add Proxmox Win11 test result to README 2026-02-24 23:03:41 +01:00
NK b241b4e805 Fix DCC2 key offset, GMSA display, and add block device support
- Fix DCC2 cached credentials: use NL$KM[0:16] as AES key instead of
  [16:32]. The secret is already stripped of its LSA_SECRET_BLOB header,
  so [16:32] was a double offset producing garbage decryption.
- Fix GMSA secrets: display managed service account passwords as hex
  instead of trying to decode binary data as UTF-16LE.
- Add raw block device support for LVM thin volumes (/dev/pve/...).
  Auto-detect block devices and route to SAM extraction. Use seek-to-end
  for device size since metadata().len() returns 0 for block devices.
- Update README with Proxmox LVM test results and Server 2025 support.
2026-02-24 23:02:12 +01:00
NK 396817c594 Add Clippy CI workflow and badge 2026-02-19 21:40:31 +01:00
NK 9a08d27c2f Replace static Rust badge with CI build status badge 2026-02-19 21:38:16 +01:00
NK 63d1e1404b Add MIT license, multi-platform CI, and README badges 2026-02-19 21:23:50 +01:00
NK 5e941b3ce3 Update gitignore and README 2026-02-19 21:11:30 +01:00
NK 0cd17ad6d9 Refactor credential extraction pipeline and add README 2026-02-19 19:49:13 +01:00
NK 9df9c2fca2 Add NTDS feature pipeline and release workflow 2026-02-19 16:21:49 +01:00
NK 6120e4a50d Add hashcat output format, flat VMDK support, and EPT walker for VBS VMs
- New --format hashcat: outputs NTLM hashes (mode 1000) and DCC2 (mode 2100)
  for direct use with hashcat
- Raw disk support: handles flat VMDKs (-flat.vmdk) and raw images (.raw/.img/.dd)
  as simple seek+read without sparse container parsing
- EPT walker: scans for nested hypervisor page tables (VBS/Hyper-V) when
  System process not found in L1 physical memory, translates L2→L1 addresses
  through Extended Page Tables to access Windows kernel structures
- Debug logging for System process scan near-misses (DTB/Flink rejections)
2026-02-11 02:19:40 +01:00
NK 5bc7e25a76 Fix MSV NT hash offset: detect DPAPI-shifted layout (NT at 0x4A not 0x36)
Win10 1607+ (build 19045) stores a 20-byte SHA/DPAPI field at +0x36 before
the actual hashes, shifting NtOwfPassword from +0x36 to +0x4A. Previous code
extracted the first 16 bytes of ShaOwPassword instead of the real NT hash.

Changes:
- Add DPAPI-shifted layout detection in structural_score(): compares data at
  0x36 with data at 0x6A (both contain ShaOwPassword/dppiGenericRandom)
- Add 6 PRIMARY_CRED_OFFSET_VARIANTS: canonical mimikatz (0x36, 0x28, 0x20),
  no-unk (0x30), and empirical DPAPI-shifted (0x4A, 0x4C)
- Replace first-match entropy selection with scored candidates, preferring
  variants with highest structural_score()
- When DPAPI layout detected: variant 0x36 gets score=0, variant 0x4A gets
  score=23 (flags validated + zero LM + DPAPI confirmed)

Verified against pypykatz: NT=bbf7d1528afa8b0fdd40a5b2531bbb6d matches
across all 3 VMware snapshots and VBox snapshot.
2026-02-10 20:51:40 +01:00
NK 423d760579 Fix multi-version support: VMware identity mapping, MSV hash validation, Win11 24H2
- VMware layer: fall back to identity mapping when VMSN has no region
  tags (older VMware snapshots), fixes "System process not found" on
  VMs with minimal VMSN metadata

- MSV physical scan: replace broken variant-0 fallback with proper
  entropy-based validation. When SHA1 cross-validation fails for all
  offset variants, check if SHA1 field is zero (not stored on Win7/2012)
  and validate hash bytes don't look like UTF-16 text. Prevents garbage
  hashes (username/domain text displayed as NT hashes) on older builds.

- Add Win11 24H2 (build 26100+) EPROCESS offsets: UniqueProcessId,
  ActiveProcessLinks, ImageFileName shifted +8 from Win10 layout

Tested on ESXi against 12 Windows VMs spanning Win7 through Win11:
  Win7, Win8/2012, Win10, Win11, Server 2012 DC, Server 2016,
  Server 2016 DC, Server 2019
2026-02-10 18:56:16 +01:00
NK f801d4f830 Add QEMU/KVM/Proxmox ELF core dump and Hyper-V .bin support
- New `qemu` feature: ELF64 core dump reader (from dump-guest-memory / virsh dump)
  Parses PT_LOAD segments for GPA→file offset mapping with binary search
- New `hyperv` feature: Hyper-V legacy .bin raw memory reader (identity mapping)
  Also handles raw dumps from MemProcFS export
- Smart format detection: magic-based (ELF header) with extension fallback
  .elf → QEMU, .bin/.raw → auto-detect ELF or Hyper-V, .sav → VBox, else VMware
- Auto-discovery: .elf, .bin, .raw files in folder mode
- Fix MSV physical scan merge: LUID=0 credentials now match existing sessions
  by username+domain instead of all colliding at HashMap key 0
2026-02-10 17:39:37 +01:00
NK dc41b621ff Fill NT AUTHORITY domain for well-known LUID sessions
When WDigest is paged out (common on VBox snapshots), SYSTEM and
service sessions have empty domain. Now fills "NT AUTHORITY" as
domain for LUIDs 0x3e7/0x3e4/0x3e5 when domain is empty, while
preserving WDigest-discovered values (e.g. WORKGROUP) when present.
2026-02-10 15:47:23 +01:00
NK 868137e2a4 Fix clippy warnings: use contains(), fix late initialization 2026-02-10 15:35:47 +01:00
NK 2c4109b8c2 Populate well-known LUID usernames and improve session display
- Fill in SYSTEM/NETWORK SERVICE/LOCAL SERVICE usernames for well-known
  LUIDs when they're empty (common on VBox where WDigest is paged out)
- Ensures DPAPI-only sessions show meaningful identifiers
2026-02-10 15:32:34 +01:00
NK 4bbe16811e Fix MSV credential merge: handle empty domain and prefer Interactive sessions
- When physical scan credential has empty domain (local logons), match
  by username only instead of requiring exact domain match
- Prefer Interactive (logon_type=2) sessions when multiple sessions
  match the same username, ensuring credentials are shown under the
  correct session entry
- Fixes VBox output showing \User instead of DESKTOP-HMI10SP\User
2026-02-10 15:26:18 +01:00
NK 31f51432df Add diagnostic logging for Kerberos physical scan results
Log count of readable vs matched candidates to aid debugging.
Most VM snapshots have Kerberos data genuinely paged out, so
the physical scan finds security principal names (false positives)
rather than actual Kerberos credential structures.
2026-02-10 15:07:11 +01:00
NK 3082facec0 Refactor MSV session discovery to merge metadata across variants
Extract common walk logic into walk_session_buckets/walk_session_list.
Use HashMap<LUID, MsvSessionInfo> instead of Vec + HashSet to allow
metadata enrichment when a session is re-discovered by a variant with
richer data (e.g. variant 2 has logon_time, variant 0 doesn't).

The inline hash table walk now tries ALL variants across ALL tables
instead of breaking on the first match, ensuring metadata from
MSV1_0_LIST_63 (variant 2) enriches sessions first found in
NlpActiveLogon (variant 0).
2026-02-10 14:46:52 +01:00
NK 37468f8973 Improve LSASS session discovery and DPAPI extraction to match pypykatz
DPAPI: Complete rewrite with correct encrypted key extraction.
- Keys at +0x34 are encrypted with LsaProtectMemory (3DES/AES), not plaintext
- Correct offsets: GUID=+0x18, keySize=+0x30, key=+0x34 (all Windows x64)
- Add SHA1 masterkey computation (inline, no external crate)
- Add physical memory scan fallback for paged-out g_MasterKeyCacheList
- Add LEA-to-.data scan as intermediate fallback between .text and .data
- All 6 DPAPI masterkeys now match pypykatz output exactly

Session discovery: Walk NlpActiveLogon + MSV hash tables + WDigest.
- New extract_msv_sessions() discovers sessions from all MSV list variants
- Resolve both LogonSessionList address and bucket count from patterns
- Walk all hash table buckets (not just the first linked list)
- Extract metadata: LogonType, SessionId, LogonServer, SID (embedded)
- WDigest l_LogSessList discovers remaining sessions (DWM, UMFD, SYSTEM)
- 8 sessions discovered (up from 2-3), matching pypykatz session count

WDigest: Validate pattern-resolved list address before use.
- File-backed .text resolution can produce stale RIP-relative offsets
- Fallback to .data scan when flink validation fails

Types: Add session metadata fields and DPAPI sha1_masterkey display.
2026-02-10 13:55:05 +01:00
NK 56f827e9ee Add process memory dump as minidump (.dmp) for pypykatz comparison
New --dump <process> flag exports a process's virtual memory as a Windows
minidump file compatible with pypykatz (lsa minidump command).

Writes 3 streams: SystemInfoStream, ModuleListStream, Memory64ListStream.
Captures present+transition+pagefile PTEs plus module VA ranges.
Supports pagefile and file-backed DLL resolution via --disk flag.

Verified: pypykatz extracts identical NT hash from our dump as our direct
extraction (bbf7d1528afa8b0fdd40a5b2531bbb6d on VMware Win10 snapshot).
2026-02-10 12:26:06 +01:00
NK cef6c57678 Fix DCC2 pad4 DWORD alignment calculation
pad4(5) was returning 6 instead of 8. Use standard (len+3)&!3.
2026-02-10 11:20:25 +01:00
NK af70499b7c Add DCC2 domain cached credential extraction from SECURITY hive
Extract MsCacheV2 (DCC2) hashes from SECURITY\Cache\NL$n values,
decrypted with the NL$KM key from LSA secrets. Output in hashcat
mode 2100 format ($DCC2$<iter>#<user>#<hash>).
2026-02-10 11:18:55 +01:00
NK e80c80afb3 Add VHD and VHDX disk image support for Hyper-V SAM extraction
- VHDX reader: full MS-VHDX spec implementation with dynamic and
  differencing disk support (BAT with interleaved sector bitmaps,
  metadata region parsing, parent locator chain)
- VHD reader: legacy VHD format with fixed, dynamic, and differencing
  disk support (big-endian BAT, per-block sector bitmaps, parent
  locator entries)
- Auto-detection: .vhd/.vhdx extensions trigger SAM mode
- Folder discovery: VHDX and VHD files auto-discovered in VM directories
- Updated CLI help text for Hyper-V disk support
2026-02-10 11:04:36 +01:00
NK 61858889e4 Fix VBox LSASS crypto extraction with .data and physical UUUR fallbacks
When file-backed resolution provides lsasrv.dll .text section, the key
init pattern is found but .data globals read as 0 (pages paged out).
Previously, the .data section fallback was only triggered when the
.text pattern wasn't found — not when all offset sets failed.

Changes:
- Fall through to .data section scan when all 7 offset sets fail
  (some .data pages may be accessible as transition pages even when
  the specific globals referenced by the pattern are paged out)
- Add physical UUUR scan as third-level fallback: enumerate all
  present+transition LSASS pages for BCRYPT_HANDLE_KEY structures,
  bypassing .data globals entirely
- Wire physical scan fallback in finder.rs

VBox results: crypto keys now extracted via .data fallback, enabling
MSV1_0 hash extraction (previously failing with "Invalid BCrypt
handle pointer: 0x0"). Pagefile resolves 998 pages (up from 0).
2026-02-10 10:39:14 +01:00
NK 57732d1a60 Scattered block bootkey scan + improved diagnostics for incomplete disks
- Add scan_blocks_for_bootkey(): scans all physically present hbin blocks
  for JD/Skew1/GBG/Data NK cells with cross-block class name resolution.
  This bypasses tree navigation entirely, finding bootkey components even
  when parent path (ControlSet→Control→Lsa) is broken.

- Wire scattered bootkey into VMDK grain scan pipeline: after fragmented
  SYSTEM hive assembly, read all hbin blocks and attempt bootkey extraction
  before falling back to regular SYSTEM hive parsing.

- Improve bootkey error diagnostics: when all extraction methods fail,
  report percentage of zero-filled pages in SYSTEM hive and explain that
  bootkey cells are in missing disk extents.

- Enhance MFTMirr fallback logging: when target files have inaccessible
  first extents, attempt zero-fill read and log whether regf/hbin data
  is present (instead of silently skipping).
2026-02-10 10:26:26 +01:00
NK 6bfd0860a2 Add MFTMirr-based NTFS fallback for incomplete disk images
When the primary MFT is inaccessible (e.g., in a truncated/missing
VMDK extent), bootstrap MFT access through $MFTMirr:
1. Parse NTFS boot sector to locate $MFTMirr
2. Read $MFT record from MFTMirr to get MFT data runs
3. Determine which MFT segments are accessible
4. Scan accessible records for SAM/SYSTEM/SECURITY files
5. Verify parent chain (config/System32) when possible
6. Fall back to regf-signature validation when parent is inaccessible

Includes full NTFS FILE record parsing: fixup arrays, attribute
enumeration, data run decoding, $FILE_NAME extraction with namespace
handling, and non-resident $DATA reading with zero-fill for
inaccessible runs.

For Windows10vstdio (50% disk coverage): MFTMirr is accessible at
partition+0x2000, MFT has 3 runs (500K records), but SAM/SYSTEM
records are in inaccessible Run 0 (records #0-204927). The fallback
correctly identifies this and falls through to grain scan.
2026-02-10 09:01:21 +01:00
NK 00b9b2980d Improve bootkey extraction for incomplete disk images
- Bypass Select key requirement: try ControlSet001/002/003 directly
  when Select key is missing from fragmented SYSTEM hive
- Phase 2c gating: detect small SYSTEM hives (< 512KB) from Phase 2b
  and allow fragmented assembly to try building a larger hive
- Relax SYSTEM hive validation: accept ControlSet001/002 in addition
  to Select for both build_hive_from_hbins and validate_hive_content
- Add brute-force NK cell scan: when tree navigation fails, scan all
  cells in assembled hive for JD/Skew1/GBG/Data bootkey components
- Add read_class_hex helper for UTF-16LE class name cell decoding
2026-02-10 08:50:38 +01:00
NK 6e77467742 Add Kerberos TGT/TGS/Client ticket extraction with .kirbi export
- Extract tickets from 3 linked lists per Kerberos logon session
  (TGT, TGS, Client) with multi-version offsets (Win7-11)
- Parse KERB_EXTERNAL_NAME for service/client principal names
- Full ASN.1 DER encoding for .kirbi (KRB-CRED) format
- Add KerberosTicket type with all fields (flags, key, timestamps, blob)
- Display tickets with type, service name, enc type, flags, times, base64 kirbi
- Add base64_encode() to crypto module
- Fix all 17 clippy warnings (is_multiple_of, div_ceil, if_same_then_else)
2026-02-10 07:51:56 +01:00
NK 4af03437f8 Fix all Clippy warnings for zero-warning compilation
- sam/mod.rs: idiomatic range contains, match destructuring, abs_diff, push char, enumerate
- windows/process.rs: array char pattern for rsplit
- lsass/msv.rs: enumerate SHA1 round loop
- main.rs: remove needless return
2026-02-10 07:35:11 +01:00
NK fd15e277a2 Improve Kerberos AVL tree extraction: add debug logging, include
credentials even without password (username+domain still valuable)
2026-02-10 07:22:58 +01:00
NK f23b0b71bb Add file-backed DLL page resolution from disk images
When Windows drops DLL .text pages from the working set, it zeros the
PTE knowing the data can be re-read from the DLL file. This commit
reads DLL files from the disk image via NTFS and serves those pages
when a zero-PTE fault occurs in a known non-writable DLL section.

Architecture:
- FileBackedResolver reads PE files from disk, extracts non-writable
  sections (.text, .rdata), maps them to module_base + VirtualAddress
- Binary search resolves VA to on-disk section data
- Integrated into ProcessMemory::read_virt() as fallback on PageFault
- Works synergistically with pagefile resolution (DLL .text enables
  pattern scans that discover structures whose data pages are in pagefile)

Results on VMware test snapshots:
- 472 sections loaded from 93 DLLs (~40 MB)
- 12,020 DLL pages resolved from disk per snapshot
- 2,235 pagefile pages resolved (up from 0 without file-backed)
- New --disk flag for single-file mode, auto-discovered in folder mode
2026-02-10 07:17:09 +01:00
NK dfc36becd5 Add multi-level pagefile resolution to page table walker
When page table pages (PDPT/PD/PT) are themselves swapped to
pagefile.sys, the parent entry becomes a pagefile PTE. The new
translate_with_pagefile() method resolves page table pages from
the pagefile at each walk level before continuing translation.

Also wire pagefile into ProcessMemory::read_virt() to resolve
data pages that are in pagefile (PageFileFault handling).
2026-02-10 07:02:09 +01:00
NK 578bdb8b5e Handle NTFS-fragmented hives in VMDK grain-direct scan
Phase 2c: fragmented hive assembly from scattered hbin blocks.
When registry hives are fragmented by NTFS (regf header at one location,
hbin blocks scattered across non-contiguous clusters), the grain scan now:

- Collects ALL hbin blocks during grain scan (not just offset=0 roots)
- Groups blocks by offset_in_hive into a candidate map
- Backtracking DFS (small hives ≤256KB): proximity-sorted candidates,
  strict then relaxed validation fallback
- Greedy assembly (large hives): first-match with zero-filled gaps
- Two-tier validation: strict (expected subkeys) → structural (root name)
- Broadened regf path matching for SYSTEM/SECURITY hives
- Default bins_size inference when no matching regf header exists

For incomplete delta disks (e.g., Windows10vstdio with 50% missing extents),
hives are now found and the error is specific ("Select not found" vs
generic "SYSTEM not found").
2026-02-10 06:44:50 +01:00
NK fa767be118 Add VMDK grain-direct scan for SAM extraction from incomplete disks
- Add scan_all_grains() to VmdkDisk: iterates physically allocated grains
  bypassing LBA translation, for fast scanning of incomplete VMDK images
- Add grain-direct fallback in SAM extraction pipeline: scans grains for
  regf/hbin signatures, assembles hives from virtual disk space
- Fix NK root key detection: remove KEY_HIVE_ENTRY (0x04) flag requirement
  since SAM's root key only has KEY_COMP_NAME (0x20)
- Add offset_in_hive validation when reading contiguous hbin blocks to
  prevent mixing blocks from different hives
- Add hive content validation (Select/Domains/Policy subkey checks) to
  reject false matches from non-system config hives
2026-02-09 06:24:30 +01:00
NK a4382362e0 Extend multi-version support to Server 2012-2025
- MSV: add Win7/8/8.1 primary credential offset variants (nt=0x20/0x28)
  with SHA1(NT) cross-validation using inline SHA1 (no external crate)
- MSV: add Win7/8/8.1 LogonSessionList code patterns (xor esi variants)
- WDigest: add Win7 CMP RDI,RBX / CMP RBX,RDI patterns
- DPAPI: add Win7/8 MASTERKEY_CACHE_ENTRY offsets with auto-detection
- Kerberos: multi-version physical scan (try +0x30 and +0x28 Password)
- Finder: rename WIN10_X64_LDR → X64_LDR (stable across Win7-11)
- Offsets: extend upper build bound to 29999 for future Server builds

Server version mapping verified:
  Server 2012 (9200), 2012R2 (9600), 2016 (14393),
  2019 (17763), 2022 (20348), 2025 (26100)
2026-02-09 05:13:33 +01:00
NK 91a570babe Multi-version Windows support (Win7 SP1 through Win11)
- EPROCESS: 5 offset tables (Win7/8/8.1/Win10 early/Win10 late+Win11)
  with auto-detection via find_system_process_auto brute-force scan
- MSV1_0: added Win7 (luid=0x30) and Win8/8.1 (luid=0x60) variants
- Kerberos: 4 offset variants with auto-detection (luid/cred_ptr/pwd differ)
- WDigest: Win10+ and Win7/8/8.1 offset variants with auto-detection
- TsPkg: 4 pTsPrimary offsets (0x40/0x70/0x80/0x90) with probing
- Credman: added Win7/8 MSV offset variants for credman_ptr
- Crypto: added Win7/8/8.1 key offset sets for IV/3DES/AES resolution
- Patterns: added Win7/8/8.1 byte patterns for lsasrv key init
- LDR offsets confirmed stable across Win7-11 (renamed to X64_LDR)
2026-02-09 04:25:36 +01:00
NK 5747f202b3 Fix LSA secret decryption: use AES-256-ECB, correct key offset
Two bugs fixed:
- Wrong AES mode: was using AES-256-CBC, should be AES-256-ECB
  (confirmed by mimikatz CRYPT_MODE_ECB, impacket per-block CBC
  reinit, pypykatz AESModeOfOperationECB)
- Wrong LSA key offset: PolEKList Secret is NT6_SYSTEM_KEYS struct
  (per mimikatz), actual key at offset 68 in decrypted blob, not 44

DefaultPassword now decrypts correctly (was garbled), DPAPI_SYSTEM
now shows correct 44-byte structure with valid version field.
2026-02-09 04:12:15 +01:00
NK 00802654c4 Add pagefile.sys resolution for paged-out LSASS memory
When a VM directory contains both memory snapshots and disk images,
open pagefile.sys from the VMDK/VDI/QCOW2 disk to resolve pages
that Windows swapped out. Uses pre-built NTFS data run map with
RefCell<Box<dyn DiskImage>> for interior mutability.

- PTE pagefile detection (bits 0/10/11 + pagefile number/offset)
- PageFileFault error variant in page table walker
- PagefileReader: opens disk, extracts pagefile.sys data runs,
  binary-search page resolution
- --disk CLI option for explicit disk image in single-file mode
- Folder mode auto-discovers disk and opens pagefile automatically
- Feature-gated behind "sam" (requires NTFS + disk image support)
2026-02-09 03:44:41 +01:00
NK fdf88e6c64 Add Makefile and improve CLI help/usage
- Makefile with release/debug/strip/install/check/clippy/test targets
- Show full help with examples when run without arguments (instead of
  cryptic clap error)
- Add --version flag, EXAMPLES section, supported input types in help
- Validate --format to text|csv|ntlm
2026-02-09 00:32:09 +01:00
NK 10b08d60bf Fix truncated process names by reading full path from PEB
EPROCESS.ImageFileName is a fixed 15-byte field, causing names like
"fontdrvhost.ex", "StartMenuExper", "VGAuthService." to be truncated.

Now reads PEB → ProcessParameters → ImagePathName (UNICODE_STRING) using
each process's own DTB for address translation, extracting just the
filename. Falls back to the 15-byte ImageFileName for kernel processes
(PEB=0) or when PEB pages are paged out.
2026-02-09 00:10:32 +01:00
NK 387c61bdb6 Fix PID 0 garbage in process listing and improve SAM scan resilience
- Skip PID 0 (System Idle Process) in enumeration: has no valid DTB,
  PEB, or name, only adds noise to the listing
- Filter ImageFileName to printable ASCII to prevent replacement
  characters from non-UTF8 bytes (e.g. 0xFF fill in Idle process)
- Add hbin-based fallback scan for NTFS-fragmented hives where regf
  header and hbin data are at non-contiguous disk locations
- Validate hive sizes: reject SYSTEM < 512KB and SAM < 16KB to avoid
  false matches (e.g. 28KB volatile "System" hive)
2026-02-08 22:44:50 +01:00
NK 2011826ed1 vmkatz: VM memory forensics tool with LSASS, SAM, and folder modes
Three extraction modes:
- LSASS: credentials from .vmem/.vmsn/.sav snapshots (9 SSP providers)
- SAM: NT/LM hashes + LSA secrets from .vdi/.vmdk/.qcow2 disk images
- Folder: auto-discover and process all VM files in a directory

Key features:
- VMware twoGbMaxExtentSparse VMDK with snapshot chain support
- VMDK descriptorless mode for orphan extent files with gap handling
- VirtualBox .sav SSM format with LZF decompression
- VDI dynamic/differencing images with parent chain
- QCOW2 L1/L2 address translation with backing file chain
- MBR/GPT partition tables, NTFS navigation via ntfs crate
- Raw regf + hbin scan fallbacks for incomplete disk images
- Hive size validation to reject false matches
- All 9 mimikatz SSP providers with physical scan fallbacks
2026-02-08 22:02:50 +01:00