Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
VMkatz — Extract Windows credentials directly from VM memory snapshots and virtual disks | Kitploit
Tools/GitHubGitHub/nikaiw/vmkatz
Password CrackingMemory ForensicsVulnerability AnalysisExploitationForensicsPost-ExploitationDigital ForensicsPenetration TestingRed TeamingIncident Response
GitHubnikaiw/vmkatz
1.5k176153h 28m agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

VMkatz

Extract Windows credentials directly from VM memory snapshots and virtual disks

View Repository

VMkatz

License: MIT Build CI Platform

You are three weeks into a red team engagement. You land on a NAS attached to the virtualization cluster — hundreds of gigabytes of .vmdk, .vmsn, .sav sitting right there. But your link does 200 KB/s. Exfiltrating a single 100 GB disk would take six days.

VMkatz exists because you shouldn't have to exfiltrate what you can read in place. It extracts Windows credentials directly from VM files — memory snapshots, virtual disks, Veeam backups: NTLM hashes, Kerberos tickets, DPAPI master keys, LSA secrets, NTDS.dit, BitLocker keys, browser secrets.

Single static binary, ~3 MB. Drop it on the ESXi host, the Proxmox node, or the NAS. Point it at a VM folder and walk away with credentials, not disk images.

What It Extracts

From memory snapshots (LSASS)

All 9 SSP credential providers that mimikatz implements:

ProviderDataNotes
MSV1_0NT/LM hashes, SHA1Physical-scan fallback for paged entries
WDigestPlaintext passwordsLinked-list walk + .data fallback
KerberosAES/RC4/DES keys, tickets (.kirbi/.ccache)AVL tree walk + ticket carving for freed sessions
TsPkgPlaintext passwordsRDP sessions only
DPAPIMaster key cache (GUID + decrypted key)SHA1 masterkey for offline DPAPI decrypt
SSPPlaintext credentialsSspCredentialList in msv1_0.dll
LiveSSPPlaintext credentialsRequires livessp.dll (rare post-Win8)
CredmanStored credentialsHash-table + single-list enumeration
CloudAPAzure AD tokensTypically empty for local-only logon

Plus: BitLocker FVEK extraction from memory (pool tag scan for FVEc/Cngb).

From virtual disks (offline)

  • SAM hashes: Local account NT/LM hashes with account status (disabled, blank password)
  • LSA secrets: Service account passwords, auto-logon credentials, machine account keys
  • Cached domain credentials: DCC2 hashes (last N domain logons)
  • DPAPI master keys: Hashcat-ready hashes ($DPAPImk$ — modes 15300/15310/15900/15910)
  • NTDS.dit: Full Active Directory hash extraction from domain controller disks (native ESE parser)
  • BitLocker decryption: Transparent disk decryption using FVEK extracted from memory

Supported Inputs

FormatExtensionsSourceStatus
VMware snapshots.vmsn + .vmemWorkstation, ESXiTested
VMware embedded snapshots.vmsn (no .vmem)ESXi suspendTested
VirtualBox saved states.savVirtualBoxTested
QEMU/KVM savevm statesauto-detectedProxmox, QEMUTested
QEMU/KVM ELF core dumps.elfvirsh dumpTested
Hyper-V saved states.vmrsHyper-V 2016+Tested
Veeam backups.vbk, .vib, .vrbVeeam B&RTested
VMware virtual disks.vmdk (sparse + flat)Workstation, ESXiTested
VirtualBox virtual disks.vdiVirtualBoxTested
QEMU/KVM virtual disks.qcow2QEMU, ProxmoxTested
Hyper-V virtual disks.vhdx, .vhdHyper-VTested
VMFS-5/6 raw SCSI devices/dev/disks/...ESXi (bypasses file locks)Tested
LVM block devices/dev/...Proxmox LVM-thinTested
Raw registry hivesSAM, SYSTEM, SECURITYreg saveTested
Raw NTDS.ditntds.dit + SYSTEMDomain controllerTested
LSASS minidump.dmpprocdump, Task ManagerTested
VM directoriesany folderAuto-discovers all filesTested

Target OS: Windows Server 2003 through Windows Server 2025 / Windows 11 24H2 (x86 PAE + x64).

Quick Start

# Extract LSASS credentials from a VMware snapshot
./vmkatz snapshot.vmsn

# With pagefile resolution for paged-out creds
./vmkatz --disk disk.vmdk snapshot.vmsn

# Extract SAM/LSA/DCC2 from a virtual disk
./vmkatz disk.vmdk

# Extract AD hashes from a domain controller disk
./vmkatz --ntds dc-disk.qcow2

# Point at a VM folder and let it find everything
./vmkatz /path/to/vm-directory/

# Extract from raw registry hives
./vmkatz SAM SYSTEM SECURITY

# Output as hashcat-ready hashes
./vmkatz --format hashcat snapshot.vmsn

# Export Kerberos tickets
./vmkatz --kirbi snapshot.vmsn        # .kirbi files
./vmkatz --ccache snapshot.vmsn       # .ccache file

# Export BitLocker FVEK for dislocker
./vmkatz --bitlocker-fvek /tmp/keys snapshot.vmsn

# Recursively scan all VMs under a path
./vmkatz -r /vmfs/volumes/datastore1/

# Parse LSASS minidump
./vmkatz lsass.dmp

# Extract from Hyper-V saved state
./vmkatz guest.vmrs

# Extract from Veeam backup (build with --features veeam)
./vmkatz backup.vbk
./vmkatz --veeam-list backup.vbk               # List disk images
./vmkatz --veeam-extract backup.vbk            # Extract raw disk

Output Formats

FormatFlagDescription
text--format text (default)Full credential dump with session metadata
brief--format briefCompact one-line-per-credential summary
ntlm--format ntlmDOMAIN\user:::hash::: pwdump format
hashcat--format hashcatRaw hashes: mode 1000 (NTLM), 2100 (DCC2), 15300/15900 (DPAPI)
csv--format csvMachine-readable, all fields

Deployment on ESXi

# Cross-compile for ESXi (musl static)
cargo build --release --target x86_64-unknown-linux-musl

# Upload and run
scp target/x86_64-unknown-linux-musl/release/vmkatz root@esxi:/tmp/
/tmp/vmkatz /vmfs/volumes/datastore1/MyVM/MyVM-Snapshot1.vmsn

When VIB protection (execInstalledOnly) is enabled, use the Python loader — no need to disable the setting:

scp tools/vmkatz_loader.py target/x86_64-unknown-linux-musl/release/vmkatz root@esxi:/tmp/
python /tmp/vmkatz_loader.py /tmp/vmkatz /vmfs/volumes/datastore1/MyVM/snapshot.vmsn

See docs/esxi.md for VIB bypass details, VMFS raw device access, and auto-discovery.

Build Features

VMkatz is modular. Features can be enabled/disabled at compile time:

FeatureDescriptionDefault
vmwareVMware .vmsn/.vmem snapshot supportYes
vboxVirtualBox .sav saved-state supportYes
qemuQEMU/KVM ELF core dumps + Proxmox savevmYes
hypervHyper-V .vmrs/.bin/.raw dump supportYes
samDisk extraction (SAM/LSA/DCC2) + disk format handlersYes
ntds.ditNTDS.dit AD extraction. Requires samYes
carveDegraded extraction from partial/truncated memoryYes
dumpProcess memory dump as minidumpYes
vmfsVMFS-5/6 raw parser for ESXi SCSI devices. Requires samYes
chromeBrowser secrets extraction (Chromium + Firefox). Requires samNo
veeamVeeam VBK/VIB/VRB backup support. Requires samNo
cargo build --release                                              # Full build
cargo build --release --no-default-features --features vmware      # VMware only
cargo build --release --no-default-features --features "sam ntds.dit"  # Disk only
cargo build --release --features chrome                            # Add chrome module
cargo build --release --features veeam                             # Add Veeam backup support

Browser secrets (experimental)

The optional chrome module extracts saved passwords, cookies, and autofill from Chromium-family browsers (Chrome, Edge, Brave, Vivaldi, Opera) via offline DPAPI decryption. Build with --features chrome, enable with --chrome.

Download Tool