Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/ivancabrera02/srhollow
Defensive ToolsPrivilege EscalationData ExfiltrationPost-ExploitationDigital ForensicsCryptographyPenetration TestingRed Teaming
GitHubivancabrera02/srhollow

SrHollow

Extracts LSA secrets and DPAPI keys from Windows registry hives via existing or newly created VSS shadow copies, with an inline regf parser and AES-256 decryption.

View Repository
586712 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

SrHollow

LSA secrets extraction, reuse a preexisting VSS shadow copy + inline regf parser + AES-256 LSA decrypt via bcrypt.dll.

Chain in 6 steps

  1. Enumerate \GLOBAL?? via NtOpenDirectoryObject + NtQueryDirectoryObject. Pick the highest-numbered HarddiskVolumeShadowCopyN.
  2. If none exists, fall back to SRSetRestorePointW(BEGIN_SYSTEM_CHANGE, DEVICE_DRIVER_INSTALL) from SrClient.dll.
  3. Enable SeBackupPrivilege in the current token (AdjustTokenPrivileges).
  4. CreateFileW("\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopyN\Windows\System32\config\{SECURITY,SYSTEM}", FILE_FLAG_BACKUP_SEMANTICS) and read to byte[].
  5. Inline regf walker parses the hive: base block, cell types nk/vk/lf/lh/li/ri/db/sk. KeyNode layout, flags @0x02, subkey list @0x1C, value list @0x28, security key @0x2C, class off @0x30, name len u16 @0x48, class len u16 @0x4A (this was a bug on first pass — Microsoft's own docs are ambiguous here), name @0x4C.
  6. Derive keys:
    • BootKey (SYSKEY): concat Class UTF-16 hex of ControlSet00N\Control\Lsa\{JD, Skew1, GBG, Data} → 16 raw bytes → permute with [8,5,4,2,11,9,13,3,0,6,1,12,14,10,15,7].
    • LSA AES-256 key from Policy\PolEKList\(default) (172 bytes): salt = bytes[0x1C..0x3C]; tmpKey = SHA-256(BootKey || salt * 1000); pt = AES-256-CBC-decrypt(bytes[0x3C..], tmpKey, IV=0); LSA key = pt[68..100].
    • Each secret under Policy\Secrets\<name>\CurrVal\(default): same layout, salt-stretch with the LSA key instead of BootKey.
    • DPAPI_SYSTEM body: bytes[4..24] = MachineKey, bytes[24..44] = UserKey. These decrypt every SYSTEM-scoped DPAPI master key on the host.

Repository layout

SrHollow/
├── README.md                          <- you are here
├── src/
│   └── SrHollow.cs                    <- inline regf parser + LSA AES crypto (~350 LOC, single file)
└── stages/
    ├── Stage1-Recon.ps1               <- read-only shadow enumeration
    ├── Stage1b-ReadShadowHives.ps1    <- auto-detect / auto-create shadow + slurp hives
    ├── Stage2-Decrypt.ps1             <- BootKey + LSA key + all secrets
    └── Stage3-Report.ps1              <- formatted operator report with OPSEC footprint

src/SrHollow.cs has zero dependencies beyond System.Security.Cryptography (which itself proxies to bcrypt.dll). It compiles as-is via Add-Type or csc.exe.

Usage

Elevated PowerShell

# 1. Read-only recon, see what shadows already exist
powershell.exe -ep bypass -File .\stages\Stage1-Recon.ps1

# 2. Extract SECURITY + SYSTEM from the newest existing shadow
#    (creates one via SRSetRestorePointW if none exist)
powershell.exe -ep bypass -File .\stages\Stage1b-ReadShadowHives.ps1

# 3. Derive BootKey + LSA key + decrypt every secret
powershell.exe -ep bypass -File .\stages\Stage2-Decrypt.ps1

# 4. (Optional) formatted operator report
powershell.exe -ep bypass -File .\stages\Stage3-Report.ps1

Requires: local admin (for SeBackupPrivilege), a Volume Shadow Copy service that is running or startable (default on Windows 10/11).

Attributable signals left when a shadow already exists:

  • One CreateFileW on \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopyN\...
  • One AdjustTokenPrivileges enabling SeBackupPrivilege
  • Standard SHA-256 + AES-CBC via bcrypt.dll (userland, unremarkable)

This is the same file-open profile as most legitimate backup agents.

Download Tool