mirror of
https://github.com/nikaiw/VMkatz
synced 2026-09-25 07:51:06 +00:00
Adds src/chrome/abe_keys.rs with a small PE/COFF reader (no new deps) plus a pattern-scanner that walks `.rdata` looking for the 3-entry Chrome ABE key table (56-byte structs, version bytes 1/2/3, 32-byte AES key per entry). The runner now opportunistically scans Program Files\<browser>\Application\<ver>\ elevation_service.exe (Chrome, Brave, Vivaldi, Opera) during the existing NTFS walk and builds a BrowserKeyMap from whichever browsers are installed. The hardcoded Chrome 135 keys remain as the fallback when no binary is found or the scan returns empty. Plumbs the keymap through abe::unwrap_app_bound_key, unwrap_app_bound_with_resolvers, decrypt_aes_encrypted_key, and disk::extract_from_disk / derive_keys. Adds a decrypt_aes_encrypted_key_with_fallback helper so legacy callers keep working. Verified on a Windows 10 VMware disk: same 83 cookies decrypted as before, log line "[chrome] extracted 3 ABE keys from chrome Program Files\Google\ Chrome\Application\135.0.7049.115\elevation_service.exe" confirms the scanner found the live binary, and a /tmp/elev_chrome135.exe roundtrip test in tests/chrome_abe_keys.rs asserts the three extracted keys match the hardcoded fallback byte-for-byte. Test suite goes from 92 to 99 passing.