github.com/crypt0p3g/dp...
#infosec #cybersecurity #redteam #pentest #opensource
github.com/crypt0p3g/dp...
#infosec #cybersecurity #redteam #pentest #opensource
"It extracts Windows secrets - NTLM hashes, DPAPI master keys, Kerberos tickets, cached domain credentials, LSA secrets, NTDS.dit, BitLocker keys - directly from VM memory snapshots and virtual disks, on the NAS, the hypervisor.." [1]
"It extracts Windows secrets - NTLM hashes, DPAPI master keys, Kerberos tickets, cached domain credentials, LSA secrets, NTDS.dit, BitLocker keys - directly from VM memory snapshots and virtual disks, on the NAS, the hypervisor.." [1]
SMB is monitored closely nowadays, stopping attacks like looting DPAPI secrets. Thanks to zblurx, NetExec got a huge upgrade, extending DPAPI credential dumping to other protocols such as WMI, WinRM and MSSQL alongside with many other similar modules🔑
SMB is monitored closely nowadays, stopping attacks like looting DPAPI secrets. Thanks to zblurx, NetExec got a huge upgrade, extending DPAPI credential dumping to other protocols such as WMI, WinRM and MSSQL alongside with many other similar modules🔑
github.com/asimons81/h...
#credentials #devops
github.com/asimons81/h...
#credentials #devops
这是一个从 Windows PowerShell 5.1 使用 .NET 的 ProtectedData 为当前用户加密秘密字符串并将其保存到文件的最小示例。
这是一个从 Windows PowerShell 5.1 使用 .NET 的 ProtectedData 为当前用户加密秘密字符串并将其保存到文件的最小示例。
A minimal example of using .NET's ProtectedData from Windows PowerShell 5.1 to encrypt a secret string for the current user and save it to a file.
A minimal example of using .NET's ProtectedData from Windows PowerShell 5.1 to encrypt a secret string for the current user and save it to a file.
Windows PowerShell 5.1から.NETのProtectedDataを使い、秘密文字列を現在ユーザー向けに暗号化してファイル保存する最小例です。
Windows PowerShell 5.1から.NETのProtectedDataを使い、秘密文字列を現在ユーザー向けに暗号化してファイル保存する最小例です。
… DPAPI で暗号化してスナップショットとして保存できるため、いつでも過去の状態へ戻せます。
・シークレット(API キー等)の誤登録検出
GitHub、AWS、Anthropic、Stripe など 35 種類以上のトークン形式を自動検出し、誤って環境変数に重要な秘密情報を平文保存しようとした際に注意を促します。
・インポート/エクスポート
.json や .reg ファイル形式での入出力に対応。
freesoft-100.com/review/envar...
… DPAPI で暗号化してスナップショットとして保存できるため、いつでも過去の状態へ戻せます。
・シークレット(API キー等)の誤登録検出
GitHub、AWS、Anthropic、Stripe など 35 種類以上のトークン形式を自動検出し、誤って環境変数に重要な秘密情報を平文保存しようとした際に注意を促します。
・インポート/エクスポート
.json や .reg ファイル形式での入出力に対応。
freesoft-100.com/review/envar...
Not ideal, but better then nothing. Too many constraints on this side project 💀
Not ideal, but better then nothing. Too many constraints on this side project 💀
CVE ID : CVE-2026-18759
Published : Aug. 4, 2026, 8:16 a.m. | 1 hour, 29 minutes ago
Description : The background service of ABP or AES runs as...
CVE ID : CVE-2026-18759
Published : Aug. 4, 2026, 8:16 a.m. | 1 hour, 29 minutes ago
Description : The background service of ABP or AES runs as...
Talk Title: Breaking Identity at Scale: From DPAPI & TBAL Secrets to Full Domain Compromise
Presented by: Paula Januszkiewicz
Learn more and see all 2026 talks: blueteamcon.com/talks-blue-t...
Talk Title: Breaking Identity at Scale: From DPAPI & TBAL Secrets to Full Domain Compromise
Presented by: Paula Januszkiewicz
Learn more and see all 2026 talks: blueteamcon.com/talks-blue-t...
@harmj0y
and
@tifkin_
at the #BHUSA Arsen…
🔁 RT @SpecterOps | reposted by @_subTee
https://x.com/SpecterOps/status/2077844494448246969
@harmj0y
and
@tifkin_
at the #BHUSA Arsen…
🔁 RT @SpecterOps | reposted by @_subTee
https://x.com/SpecterOps/status/2077844494448246969
ADFS token-signing keys stored in Machine DPAPI can be recovered by SYSTEM-level processes without touching LSASS, enabling Golden SAML attacks that bypass MFA.
-
IOCs: (None identified)
-
#ADFS #DPAPI #GoldenSAML #ThreatIntel
ADFS token-signing keys stored in Machine DPAPI can be recovered by SYSTEM-level processes without touching LSASS, enabling Golden SAML attacks that bypass MFA.
-
IOCs: (None identified)
-
#ADFS #DPAPI #GoldenSAML #ThreatIntel
執筆者: Shebin Mathew はじめに 2017年にCyberArkの研究者が初めて報告し、2021年にはMandiantの研究者がさらに詳細を明らかにした「Golden SAML」という手法は、Microsoftエコシステムにおいて脅威アクターがID主張を偽造する最も効果的な手段の一つであり続けて...
執筆者: Shebin Mathew はじめに 2017年にCyberArkの研究者が初めて報告し、2021年にはMandiantの研究者がさらに詳細を明らかにした「Golden SAML」という手法は、Microsoftエコシステムにおいて脅威アクターがID主張を偽造する最も効果的な手段の一つであり続けて...