Files
NK d616a62775 v1.0.0: major rewrite — minidump support, pre-Vista, verified offsets, carve mode
LSASS credential extraction:
- Minidump (.dmp) support: full MSV/Kerberos/DPAPI/WDigest/TsPkg/SSP/
  LiveSSP/CredMan/CloudAP extraction from LSASS minidumps
- Pre-Vista (WinXP/Win2003): 32-bit EPROCESS, PAE paging, DES-X-CBC/RC4
- Win11 24H2 (26100+): correct EPROCESS offsets, MSV LIST_64/LIST_65,
  Kerberos variant with shifted offsets
- All MSV/SSP/LiveSSP/CloudAP/CredMan/WDigest offsets verified against
  mimikatz C structs and pypykatz templates
- EPROCESS offsets verified against Vergilius Project (13 variants)
- AES-CFB-128 cipher for non-8-aligned LSASS blobs
- DPAPI extraction from dpapisrv.dll (Win10 19041+ moved g_MasterKeyCacheList)
- Adaptive MSV offset discovery with build-number-aware variant ordering
- MSV NT hash fix: validated variant tracking + DPAPI cross-check for
  human accounts (SHA1 validation only works for machine accounts)
- Kerberos: AES/DES/RC4 key extraction, kirbi/ccache export, ticket
  quality validation, false positive filtering
- CloudAP: PRT blob extraction, 7 patterns covering Win10 1507–Win11 24H2
- CredMan: correct 2-level navigation (SET_LIST→STARTER→entry)
- Garbage filtering: repeating pattern detection, structural score
  validation, unknown etype rejection

Architecture:
- Carve mode: two-level degraded extraction for truncated memory files
- sam/mod.rs split into 4 submodules (partition, ntfs_reader,
  disk_fallbacks, vmdk_scan)
- ProviderStatus enum replacing string-based status tracking
- Safe read helpers (utils.rs) replacing 86 try_into().unwrap() calls
- GovmemError renamed to VmkatzError across all 35 source files
- Named paging constants (PAGE_PHYS_MASK, LARGE_*_MASK)

Performance:
- TLB cache for page table translation (256-entry direct-mapped)
- QCOW2 L2 table caching (64 tables, amortized I/O)
- VMware region binary search (partition_point)
- Stack-allocated ASN.1 length encoding, IV entropy histogram
- Single-pass System process + EPT scanning
- memchr::memmem for pattern matching

Robustness:
- Minidump parser hardening (bounds checks, overflow protection)
- PE32 validation (machine type, section count, optional header size)
- Multiple pagefile support (PTE pagefile_number routing)
- VMware embedded memory support (.vmss/.vmsn without .vmem)
- EPT false positive prevention (reserved bits, PDPT validation)
- VMEM truncation detection with user warning

Testing:
- 8 automated tests (4 unit + 4 integration)
- Non-regression framework: compare.py + esxi_test.sh
- All credentials verified against pypykatz on 10+ minidumps

CLI:
- --all/-a: show empty sessions (hidden by default)
- --no-ept: skip EPT scanning
- --kirbi/--ccache: Kerberos ticket export
- Silent output modes: ntlm, hashcat, text summary
- Hex display for non-printable machine account passwords
2026-03-09 16:21:24 +01:00

124 lines
3.5 KiB
Makefile

BINARY_NAME := vmkatz
TARGET_DIR := target
MUSL_TARGET := x86_64-unknown-linux-musl
SHELL := bash
.PHONY: default
default: release
.PHONY: release
release:
cargo build --release
@cp $(TARGET_DIR)/release/$(BINARY_NAME) ./$(BINARY_NAME)
@echo "[+] Built: ./$(BINARY_NAME) ($$(du -h ./$(BINARY_NAME) | cut -f1))"
.PHONY: release-musl
release-musl:
RUSTUP_HOME=$(CURDIR)/.rustup cargo build --release --target $(MUSL_TARGET)
@cp $(TARGET_DIR)/$(MUSL_TARGET)/release/$(BINARY_NAME) ./$(BINARY_NAME)-musl
@echo "[+] Built: ./$(BINARY_NAME)-musl ($$(du -h ./$(BINARY_NAME)-musl | cut -f1))"
.PHONY: release-minimal
release-minimal:
cargo build --release --no-default-features --features vmware
@cp $(TARGET_DIR)/release/$(BINARY_NAME) ./$(BINARY_NAME)-minimal
@echo "[+] Built: ./$(BINARY_NAME)-minimal ($$(du -h ./$(BINARY_NAME)-minimal | cut -f1))"
.PHONY: debug
debug:
cargo build
@echo "[+] Built: $(TARGET_DIR)/debug/$(BINARY_NAME)"
.PHONY: check
check:
cargo check
.PHONY: clippy
clippy:
cargo clippy -- -D warnings
.PHONY: fmt
fmt:
cargo fmt
.PHONY: fmt-check
fmt-check:
cargo fmt -- --check
.PHONY: clean
clean:
cargo clean
@rm -f ./$(BINARY_NAME) ./$(BINARY_NAME)-musl ./$(BINARY_NAME)-minimal
.PHONY: install
install: release
@mkdir -p $(HOME)/.local/bin
cp ./$(BINARY_NAME) $(HOME)/.local/bin/$(BINARY_NAME)
@echo "[+] Installed: $(HOME)/.local/bin/$(BINARY_NAME)"
.PHONY: ci
ci: fmt-check clippy unit-test
.PHONY: unit-test
unit-test:
cargo test
.PHONY: test-lsass
test-lsass: release
./$(BINARY_NAME) --format ntlm "/home/user/vmware/Windows 10 x64/Windows 10 x64-Snapshot1.vmsn"
.PHONY: test-sam
test-sam: release
./$(BINARY_NAME) --format ntlm "/home/user/vm/windows10-clean/windows10-clean.vdi"
.PHONY: test-folder
test-folder: release
./$(BINARY_NAME) "/home/user/vmware/Windows 10 x64/"
.PHONY: test
test: test-lsass test-sam test-folder
.PHONY: regression
regression: release
./scripts/esxi_test.sh --host esx2
.PHONY: regression-all
regression-all: release
./scripts/esxi_test.sh --host all
.PHONY: help
help:
@echo "vmkatz - VM memory forensics credential extractor"
@echo ""
@echo "Build targets:"
@echo " make Build release binary (default)"
@echo " make release Build optimized release binary → ./vmkatz"
@echo " make release-musl Build static musl binary → ./vmkatz-musl"
@echo " make release-minimal VMware-only minimal binary → ./vmkatz-minimal"
@echo " make debug Build debug binary → target/debug/vmkatz"
@echo " make install Install to ~/.local/bin/"
@echo " make clean Remove build artifacts"
@echo ""
@echo "Quality:"
@echo " make ci Run full CI pipeline (fmt + clippy + tests)"
@echo " make check Run cargo check"
@echo " make clippy Run clippy lints"
@echo " make fmt Format code"
@echo " make fmt-check Check formatting"
@echo " make unit-test Run unit tests"
@echo ""
@echo "Tests:"
@echo " make test Run all integration tests"
@echo " make test-lsass Test LSASS extraction (VMware)"
@echo " make test-sam Test SAM extraction (VBox VDI)"
@echo " make test-folder Test folder discovery (VMware)"
@echo " make regression Non-regression test vs pypykatz (esx2)"
@echo " make regression-all Non-regression test vs pypykatz (all hosts)"
@echo ""
@echo "Release profile: strip=true, lto=true, codegen-units=1, panic=abort"
@echo "Default features: vmware,vbox,qemu,hyperv,sam,ntds.dit,carve,dump"
@echo "Override: cargo build --release --no-default-features --features vmware,sam"