mirror of
https://github.com/nikaiw/VMkatz
synced 2026-09-25 07:51:06 +00:00
Three extraction modes: - LSASS: credentials from .vmem/.vmsn/.sav snapshots (9 SSP providers) - SAM: NT/LM hashes + LSA secrets from .vdi/.vmdk/.qcow2 disk images - Folder: auto-discover and process all VM files in a directory Key features: - VMware twoGbMaxExtentSparse VMDK with snapshot chain support - VMDK descriptorless mode for orphan extent files with gap handling - VirtualBox .sav SSM format with LZF decompression - VDI dynamic/differencing images with parent chain - QCOW2 L1/L2 address translation with backing file chain - MBR/GPT partition tables, NTFS navigation via ntfs crate - Raw regf + hbin scan fallbacks for incomplete disk images - Hive size validation to reject false matches - All 9 mimikatz SSP providers with physical scan fallbacks
4 lines
20 B
Plaintext
4 lines
20 B
Plaintext
/target
|
|
vmkatz
|
|
*.py
|