Skip to content
KitploitKITPLOIT
StrumentiExploitsBlog
Log in
Invia
StrumentiExploitsBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
Strumenti/GitHubGitHub/zblurx/dploot
Encryption/Decryption ToolsPost-ExploitationDigital ForensicsPenetration TestingCloud SecurityRed Teaming
GitHubzblurx/dploot

dploot

Loot and decrypt Windows DPAPI secrets remotely or offline, including masterkeys, credentials, vaults, certificates, browser data, and cached Azure tokens.

Vedi Repository
555751715 giorni faRevisionato da Kitploit

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi
Contenuto non disponibile nella lingua richiesta. Visualizzazione della versione inglese.

dploot

dploot is Python rewrite of SharpDPAPI written in C# by Harmj0y, which is itself a port of DPAPI from Mimikatz by gentilkiwi. It implements all the DPAPI logic of these tools, but this time it is usable with a python interpreter and from a Linux environment.

If you don't know what is DPAPI, check out this post.

Table of Contents

  • dploot
    • Table of Contents
    • Installation
    • Usage
      • Protocols
      • Kerberos
    • How to use
      • Remote access via SMB
      • Remote access via WMI
      • Remote access via WinRM
      • Remote access via MSSQL
      • Local filesystem access
      • Remote access via Cobalt Strike
      • As a domain administrator
      • As a non-domain administrator
    • Commands
      • User Triage
        • masterkeys
        • credentials
        • vaults
        • rdg
        • certificates
        • browser
        • cng
        • wam
        • mobaxterm
        • triage
      • Machine Triage
        • machinemasterkeys
        • machinecredentials
        • machinevaults
        • machinecertificates
        • machinecng
        • machinetriage
      • Misc
        • wifi
        • sccm
        • backupkey
        • blob
    • Credits

Installation

You can install dploot directly from PyPI with pipx:

pipx install git+https://github.com/zblurx/dploot.git

OR

pipx install dploot

On Kali Linux, you can install dploot from the repositories:

sudo apt install python3-dploot

Usage

dploot (https://github.com/zblurx/dploot) v4.0.0 by @_zblurx
usage: dploot [-h]
              {backupkey,blob,browser,certificates,cng,credentials,machinecertificates,machinecng,machinecredentials,machinemasterkeys,machinetriage,machinevaults,masterkeys,mobaxterm,rdg,sccm,triage,vaults,wam,wifi}
              ...

DPAPI looting in Python

positional arguments:
  {backupkey,blob,browser,certificates,cng,credentials,machinecertificates,machinecng,machinecredentials,machinemasterkeys,machinetriage,machinevaults,masterkeys,mobaxterm,rdg,sccm,triage,vaults,wam,wifi}
                        Action
    backupkey           Backup Keys from domain controller
    blob                Decrypt DPAPI blob. Can fetch masterkeys on target
    browser             Dump users credentials and cookies saved in browser from local or remote target
    certificates        Dump users certificates from local or remote target
    cng                 Dump users CNG files blob from local or remote target
    credentials         Dump users Credential Manager blob from local or remote target
    machinecertificates
                        Dump system certificates from local or remote target
    machinecng          Dump system CNG files from local or remote target
    machinecredentials  Dump system credentials from local or remote target
    machinemasterkeys   Dump system masterkey from local or remote target
    machinetriage       Loot SYSTEM Masterkeys (if not set), SYSTEM credentials, SYSTEM certificates and SYSTEM vaults from local or remote target
    machinevaults       Dump system vaults from local or remote target
    masterkeys          Dump users masterkey from local or remote target
    mobaxterm           Dump Passwords and Credentials from MobaXterm
    rdg                 Dump users saved password information for RDCMan.settings from local or remote target
    sccm                Dump SCCM secrets (NAA, Collection variables, tasks sequences credentials) from local or remote target
    triage              Loot Masterkeys (if not set), credentials, rdg, certificates, browser and vaults from local or remote target
    vaults              Dump users Vaults blob from local or remote target
    wam                 Dump users cached azure tokens from local or remote target
    wifi                Dump wifi profiles from local or remote target

options:
  -h, --help            show this help message and exit

Protocols

dploot v4.0.0+ supports multiple network protocols for remote access. You select the protocol using --protocol <protocol_name>. Each protocol has different capabilities and requirements:

  • smb (default): Uses SMB/RPC for remote file access and registry operations. Works with most Windows targets. Supports Kerberos authentication. Works with impacket
  • wmi: Uses Windows Management Instrumentation (DCOM) for remote execution and registry operations. Useful alternative to SMB. Supports Kerberos authentication. Works with impacket
  • winrm: Uses Windows Remote Management for PowerShell-based operations. Common in modern environments. Works with pypsrp
  • mssql: Connects via MSSQL Server. Supports both domain and local database authentication. Supports Kerberos authentication. Works with impacket
  • local: Accesses a mounted or copied Windows filesystem directly (no network connection needed). Useful for offline analysis of physical drives or disk images.
  • cobaltstrike: Executes operations through a Cobalt Strike beacon REST API. Useful for red team operations with Cobalt Strike infrastructure.

Example using WMI protocol:

$ dploot masterkeys --protocol wmi -d waza.local -u Administrator -p 'Password!123' -t 192.168.57.5

Example using local protocol (offline filesystem):

$ dploot masterkeys --protocol local --root /mnt/c_drive -u bob -p Password

Important notes on command support:

  • Most commands support all protocols. However, backupkey only works with SMB protocol (requires domain controller access).
  • Only smb protocol supports LSA dump to automaticaly dump the DPAPI machine key. For the other protocols, you will have to bring it by yourself with --dpapi-system-key.

Kerberos

dploot can authenticate with Kerberos for the smb, wmi, and mssql protocols. Use -k to enable Kerberos with NTLM fallback. If you want to use a cached ticket, use --use-kcache. To use an AES key, use --aesKey.

$ dploot masterkeys -d waza.local -u Administrator -k -t 192.168.57.5

How to use

The goal of dploot is to simplify DPAPI related loot from a Linux box. How you use this tool depends on your access level and target configuration.

Remote access via SMB

The default protocol is SMB. This is the most common approach for DPAPI looting and works with standard Windows file sharing:

$ dploot masterkeys -d waza.local -u Administrator -p 'Password!123' -t 192.168.57.5
[*] Connected to 192.168.57.5 as waza.local\Administrator (admin)

[*] Triage ALL USERS masterkeys

{d305b55b-f0ca-40cf-b04c-3620aa5da427}:6f45f9ee77014df8a68104abd0e8d5eadb3d9f22
{d37fa151-d670-4c58-9d70-3233b4918942}:8709574524ad35ef0b3a114b93990f8490d86cba

Remote access via WMI

WMI provides an alternative to SMB for remote access and is useful when SMB is restricted:

Scarica lo strumento