Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
KeeFarceReborn — A standalone DLL that exports databases in cleartext once injected in the KeePass process. | Kitploit
Tools/GitHubGitHub/d3lb3/keefarcereborn
Password AttacksPayload GenerationData ExfiltrationPost-ExploitationRed TeamingShellcode Generation
GitHubd3lb3/keefarcereborn

KeeFarceReborn

A standalone DLL that exports databases in cleartext once injected in the KeePass process.

View Repository
29935233 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

KeeFarce Reborn

A standalone DLL that exports databases in cleartext once injected in the KeePass process.

Heavily inspired by the great KeeFarce, KeeThief and KeePassHax projects.

Yet another KeePass extraction tool, why ?

A few years ago, @denandz released KeeFarce, the first offensive tool designed to extract KeePass databases in cleartex. It works by injecting a DLL into the running process, then walks the heap using ClrMD to find the necessary objects and invoke KeePass's builtin export method using reflection. Its only downside at the time was that multiple files needed to be dropped on the target (the extraction DLL + ClrMD DLL + the injector + a bootstrap DLL).

A year later, @tifkin_ and @harmj0y released an in-depth review of offensive techniques targeting KeePass (while not available on harmj0y's blog anymore, the articles can be found on Wayback Machine: part 1, part 2). It resulted in the release of KeeThief, a tool able to decrypt KeePass' masterkey (including when alternative authentication method are used). It worked so well that KeePass developpers added a parameter to mitigate this technique (it can be disabled by editing KeePass configuration file if the user have enough rights, which is pretty common).

These tools quickly became my go-to during penetration testing, but they soon became obsolete as their injection techniques (namely, the famous Win32 APIs gang of VirtualAllocEx, WriteProcessMemory, CreateRemoteThread, WriteProcessMemory, etc) now immediately triggers detection. @snovvcrash addressed this issue by forking KeeThief (now in a private repo, but still accessible here) to improve the injection mechanism with D/Invoke, writing a great article detailing the process he followed. While it demonstrated the faisability of maintaining KeeThief, I find it difficult to regularly implement new injection techniques, as KeeThief's code is tightly linked to its injector.

@holly-cracker also released KeePassHax, which comes as a single DLL and only uses reflection to decrypt KeePass' masterkey. Inspired by this work, I decided to do the same with KeeFarce and write my own KeePass extraction tool with the following features:

  • Self-sufficient ⇒ no interaction needed with the injector's code to work.
  • Only uses builtin .NET libraries (no ClrMD) ⇒ better compatibility + single-file DLL makes the injection process easier.
  • Exports the database (like KeeFarce) ⇒ no need to retrieve the .kdbx nor using a custom KeePass build to input the recovered masterkey.

KeeFarce Reborn also provides a KeePass plugin DLL to make KeePass inject itself without bothering with injectors!

Building

As the code solely relies on .NET Framework with no external dependency, it should compile easily on Visual Studio 2015 and higher.

Usage Example

KeeFarce Reborn does not include an injector to load the DLL in KeePass process. This is deliberate, as injectors become obsolete every few months you will have to use your own. The following parts demonstrate two typical ways to perform injection.

Make KeePass inject KeeFarce Reborn as a plugin

Pre-requisite: write access to KeePass plugin directory.

KeePass features a plugin framework to provide additional functionalities to users. It works by loading a DLL into KeePass process, allowing plugin developers to perform actions within KeePass' application domain.

As a result, we can abuse this functionality to load KeeFarce Reborn as a plugin, without even having to use an external injector! You just need to compile KeeFarceRebornPlugin project and copy the DLL into the plugins directory (located at at KeePass root, namely "C:\Program Files\KeePass Password Safe 2\Plugins" for a global install).

For the project to build correctly, you will need to copy the targeted KeePass.exe assembly version to KeeFarceRebornPlugin directory, or use the PLGX if you want the resulting plugin to be compatible with any KeePass version.

Next time KeePass is started and a database unlocked, the DLL will be loaded and the injection performed. If KeePass is already running, you will need to wait for its next restart for the injection to occur (or force the restart yourself).

⚠️ Once a plugin is loaded, the DLL file will be write-protected until KeePass is closed. Keep that in mind to make sure that you don't leave malicious plugins behind you during assessments.

If you don't have write access to KeePass plugin directory, you can have a look at Quarkslab's article which demonstrates how to load plugins with less privileges through the plugin cache.

Perform shellcode injection

Pre-requisite: KeePass is running + a database in unlocked by the user + you have enough rights to inject in the KeePass process.

Because I personally find it easier to stealthily inject shellcode than DLL in a remote process, the first thing I typically start with is generating a position-independent shellcode from our DLL. It appears that @odzhan and @TheWover's donut project perfectly suits our needs !

We compile donut from a commit in the dev branch, as it fixes an issue in application domain management that would prevent us from performing reflection in the default domain.

git clone https://github.com/TheWover/donut/
cd donut
git checkout 9d781d8da571eb1499122fc0e2d6e89e5a43603c

We can easily build from Visual Studio's x64 Native Tools Command Prompt with nmake utility:

nmake -f Makefile.msvc

Generating the shellcode is as simple as:

.\donut.exe "C:\KeeFarceReborn\KeePassReborn\bin\Release\KeeFarceReborn.dll" -c KeeFarceReborn.Program -m Main -e 1

  [ Donut shellcode generator v0.9.3
  [ Copyright (c) 2019 TheWover, Odzhan

  [ Instance type : Embedded
  [ Module file   : "C:\KeeFarceReborn\KeePassReborn\bin\Release\KeeFarceReborn.dll"
  [ Entropy       : None
  [ File type     : .NET DLL
  [ Class         : KeeFarceReborn.Program
  [ Method        : Main
  [ Target CPU    : x86+amd64
  [ AMSI/WDLP     : continue
  [ Shellcode     : "loader.bin"

Note that -e 1 is necessary to disable entropy, otherwise the injected process won't be in the default application domain.

Let's compress it using PowerShell for easier integration in the injector's code:

Download Tool