Skip to content

live dpapi

skelsec edited this page Apr 14, 2021 · 2 revisions

LIVE DPAPI

The submodules under DPAPI will provide three sets of commands.

  1. Acquires ALL DPAPI key material that will help you to decrypt every DPAPI protected secrets stored on the machine you execute pypykatz on. keys
  2. This help you to decrypt secrets which were protected with DPAPI under the CURRENT USER's context. vpol vcred cred blob blobfile securestring securestringfile chrome
  3. Acquire credentials which stored with the machine account wifi

Other stuff

For the terminology, working of DPAPI pls check the 'normal' DPAPI wiki page

Clone this wiki locally