
dpapi-toolkit
Drop any Windows DPAPI artifact and it identifies the format and the exact master key it needs, then decrypts once you supply the key. Offline, CLI +…

Drop any Windows DPAPI artifact and it identifies the format and the exact master key it needs, then decrypts once you supply the key. Offline, CLI +…

CredsHunter - Credential Hunting scripts for Windows and Linux OS

Brute-force tool that recovers full executable paths from Windows prefetch hashes using bodyfiles, supporting XP, Vista, and 2008 hash functions for…

Retrieves the master password from Keepass memory dump, using a hint of bruteforce.

Python module for viewing Portable Executable (PE) files in a tree-view using pefile and PyQt5. Can also be used with IDA Pro and Rekall to dump…


Dump TeamViewer ID and password from memory. Works much better than other tools.

KeePass Master Password Extraction PoC for Linux

Retrieve the master password of a keepass database <= 2.53.1

Offset Independent Credential Extraction Tool

Extracts KeePass master passwords from memory dumps of unlocked databases, outputting potential characters by position, a passphrase, and a…