#DPAPI
Drop any Windows DPAPI artifact and it identifies the format and the exact master key it needs, then decrypts once you supply the key. Offline, CLI + web UI.

github.com/crypt0p3g/dp...

#infosec #cybersecurity #redteam #pentest #opensource
GitHub - crypt0p3g/dpapi-toolkit: Drop any Windows DPAPI artifact and it identifies the format and the exact master key it needs, then decrypts once you supply the key. Offline, CLI + web UI.
Drop any Windows DPAPI artifact and it identifies the format and the exact master key it needs, then decrypts once you supply the key. Offline, CLI + web UI. - crypt0p3g/dpapi-toolkit
github.com
September 25, 2026 at 10:50 AM
dpapi-toolkit — Drop any Windows DPAPI artifact and it identifies the format and the exact master key it needs, then decrypts once you supply the key. Offline, CLI + web UI. https://ktp.sh/6RkMvHlXIr
September 24, 2026 at 11:02 PM
On a recent Incident response case, we encountered VMkatz.

"It extracts Windows secrets - NTLM hashes, DPAPI master keys, Kerberos tickets, cached domain credentials, LSA secrets, NTDS.dit, BitLocker keys - directly from VM memory snapshots and virtual disks, on the NAS, the hypervisor.." [1]
GitHub - nikaiw/VMkatz: Extract Windows credentials directly from VM memory snapshots and virtual disks
Extract Windows credentials directly from VM memory snapshots and virtual disks - nikaiw/VMkatz
github.com
September 22, 2026 at 4:46 AM
ItsNotAlwaysSMB: DPAPI in other protocols🔥

SMB is monitored closely nowadays, stopping attacks like looting DPAPI secrets. Thanks to zblurx, NetExec got a huge upgrade, extending DPAPI credential dumping to other protocols such as WMI, WinRM and MSSQL alongside with many other similar modules🔑
September 14, 2026 at 2:01 PM
🐍 Python 3.11+, MIT licensed, installs via uv or pipx. Runs natively on Windows with optional DPAPI master-key wrapping
github.com/asimons81/h...
#credentials #devops
GitHub - asimons81/hermes-vault: Hermes-native local-first credential broker, scanner, and encrypted vault.
Hermes-native local-first credential broker, scanner, and encrypted vault. - asimons81/hermes-vault
github.com
September 13, 2026 at 12:59 AM
不要将秘密字符串放在明文文件中 — 从 PowerShell 调用 Windows DPAPI

这是一个从 Windows PowerShell 5.1 使用 .NET 的 ProtectedData 为当前用户加密秘密字符串并将其保存到文件的最小示例。
不要将秘密字符串放在明文文件中 — 从 PowerShell 调用 Windows DPAPI
这是一个从 Windows PowerShell 5.1 使用 .NET 的 ProtectedData 为当前用户加密秘密字符串并将其保存到文件的最小示例。
papanda925.com
September 7, 2026 at 3:25 AM
Do Not Put Secret Strings in Plaintext Files ― Calling Windows DPAPI from PowerShell

A minimal example of using .NET's ProtectedData from Windows PowerShell 5.1 to encrypt a secret string for the current user and save it to a file.
Do Not Put Secret Strings in Plaintext Files ― Calling Windows DPAPI from PowerShell
A minimal example of using .NET's ProtectedData from Windows PowerShell 5.1 to encrypt a secret string for the current user and save it to a file.
papanda925.com
September 7, 2026 at 3:20 AM
秘密文字列を平文ファイルに置かない ― Windows DPAPIをPowerShellから呼ぶ

Windows PowerShell 5.1から.NETのProtectedDataを使い、秘密文字列を現在ユーザー向けに暗号化してファイル保存する最小例です。
秘密文字列を平文ファイルに置かない ― Windows DPAPIをPowerShellから呼ぶ
Windows PowerShell 5.1から.NETのProtectedDataを使い、秘密文字列を現在ユーザー向けに暗号化してファイル保存する最小例です。
papanda925.com
September 7, 2026 at 3:00 AM
A new Windows backdoor named Sleepwalker has been discovered, which remains dormant until activated by a specific network packet. It features a unique command language with 23 instructions for executing tasks like data exfiltration and code execution. The malware masquerades as Microsoft's dpapi.
You don't want this Sleepwalker backdoor on your Windows machine
www.theregister.com
August 26, 2026 at 9:14 AM
↓

… DPAPI で暗号化してスナップショットとして保存できるため、いつでも過去の状態へ戻せます。

・シークレット(API キー等)の誤登録検出
GitHub、AWS、Anthropic、Stripe など 35 種類以上のトークン形式を自動検出し、誤って環境変数に重要な秘密情報を平文保存しようとした際に注意を促します。

・インポート/エクスポート
.json や .reg ファイル形式での入出力に対応。

freesoft-100.com/review/envar...
Windowsの環境変数を安全に管理できる GUI 環境変数エディター「Envarly」
Windowsの環境変数を安全に管理できる GUI 環境変数エディター「Envarly」の評価とレビュー、ダウンロードや使い方を解説します。Windows 10/11 向けの GUI 環境変数マネージャーです。標準の「環境変数」設定画面では行いにくかった PATH の並べ替えや確認作業を、直感的かつ…
freesoft-100.com
August 17, 2026 at 12:42 PM
Forcing users to auth on first activation and saving the conn string to a reg key after passing it through DPAPI. Only the encrypted bytes are stored. The client app decrypts > connects > queries > kills the plaintext.

Not ideal, but better then nothing. Too many constraints on this side project 💀
August 6, 2026 at 1:15 PM
CVE-2026-18759 - An improper authentication and path traversal vulnerability exists in ASUSTOR Backup Plan and ASUSTOR EZ Sync.
CVE ID : CVE-2026-18759

Published : Aug. 4, 2026, 8:16 a.m. | 1 hour, 29 minutes ago

Description : The background service of ABP or AES runs as...
CVE-2026-18759 - An improper authentication and path traversal vulnerability exists in ASUSTOR Backup Plan and ASUSTOR EZ Sync.
The background service of ABP or AES runs as NT AUTHORITY\SYSTEM and implements a file-based inter-process communication (IPC) mechanism protected by AES encryption. Because the encryption key file is readable by standard users and protected using DPAPI. Any authenticated local user can recover the key and forge valid IPC requests. …
cvefeed.io
August 4, 2026 at 10:00 AM
No zero-days. No commercial C2. Just open-source tooling and a full infostealer kill chain against default Windows 11 UAC, run live by every attendee. Filipi Pires shows why DPAPI isn't the boundary you think it is. 🤔
July 29, 2026 at 2:00 PM
🚨Blue Team Con 2026 Talk Alert🚨

Talk Title: Breaking Identity at Scale: From DPAPI & TBAL Secrets to Full Domain Compromise

Presented by: Paula Januszkiewicz

Learn more and see all 2026 talks: blueteamcon.com/talks-blue-t...
July 16, 2026 at 11:01 PM
Nemesis 2.2 brings new capabilities for offensive security teams, from full disk image ingestion and automated DPAPI decryption to AI-assisted finding triage.

@harmj0y
and
@tifkin_
at the #BHUSA Arsen…

🔁 RT @SpecterOps | reposted by @_subTee
https://x.com/SpecterOps/status/2077844494448246969
July 16, 2026 at 10:28 PM
Attackers can exploit 'Ghost Certificates' in ADFS to forge high-privilege SAML tokens, bypassing MFA. Learn how to defend against this stealthy threat. 👻🔒 #CyberSecurity #ADFS #ThreatDetection
Recovering Active ADFS Signing Keys via Machine DPAPI | Google Cloud Blog
This post details how adversaries exploit this TTP to forge high-privilege SAML tokens and provide the blueprint to defend against it.
cloud.google.com
July 16, 2026 at 6:39 AM
Recovering Active ADFS Signing Keys via Machine DPAPI | Google Cloud Blog: cloud.google.com/blog/topics/...
Recovering Active ADFS Signing Keys via Machine DPAPI | Google Cloud Blog
This post details how adversaries exploit this TTP to forge high-privilege SAML tokens and provide the blueprint to defend against it.
cloud.google.com
July 9, 2026 at 11:25 PM
Recovering Active ADFS Signing Keys via Machine DPAPI
Recovering Active ADFS Signing Keys via Machine DPAPI
cloud.google.com
July 8, 2026 at 5:54 AM
@mandiant.com
ADFS token-signing keys stored in Machine DPAPI can be recovered by SYSTEM-level processes without touching LSASS, enabling Golden SAML attacks that bypass MFA.
-
IOCs: (None identified)
-
#ADFS #DPAPI #GoldenSAML #ThreatIntel
Recovering Active ADFS Signing Keys via Machine DPAPI
cloud.google.com
July 7, 2026 at 8:17 PM
Mandiant found a "ghost" ADFS certificate entry can expose the active signing key via Machine DPAPI when AutoCertificateRollover is off, enabling forged SAML assertions, MFA bypass, and access to Microsoft 365 and Entra ID. #ADFS #GoldenSAML #EntraID
The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI
Mandiant showed that in ADFS environments with AutoCertificateRollover disabled and manual certificate rotation, a “ghost” certificate entry can leave the active token-signing key recoverable from Machine DPAPI. If that key is obtained, attackers can forge SAML assertions to impersonate users, bypass MFA, and gain access to federated services such as Microsoft 365 and Entra ID. #ADFS #EntraID #Microsoft365 #GoldenSAML
www.hendryadrian.com
July 7, 2026 at 6:45 PM
マシンDPAPI経由でアクティブなADFS署名鍵を復元する手法

執筆者: Shebin Mathew はじめに  2017年にCyberArkの研究者が初めて報告し、2021年にはMandiantの研究者がさらに詳細を明らかにした「Golden SAML」という手法は、Microsoftエコシステムにおいて脅威アクターがID主張を偽造する最も効果的な手段の一つであり続けて...
マシンDPAPI経由でアクティブなADFS署名鍵を復元する手法
執筆者: Shebin Mathew はじめに  2017年にCyberArkの研究者が初めて報告し、2021年にはMandiantの研究者がさらに詳細を明らかにした「Golden SAML」という手法は、Microsoftエコシステムにおいて脅威アクターがID主張を偽造する最も効果的な手段の一つであり続けて
blackhatnews.tokyo
July 7, 2026 at 5:06 PM