Skip to content
KitploitKITPLOIT
ИнструментыЭксплойтыБлог
Log in
Отправить
ИнструментыЭксплойтыБлог
Отправить

Инструменты для хакинга, пентеста и кибербезопасности — ваш арсенал защиты!

Kitploit — это каталог инструментов для хакинга, кибербезопасности и пентестинга. Находите последние обновления проектов для поиска уязвимостей, анализа систем, автоматизации тестирования и усиления вашей безопасности.

··Ленты·Контакты·Конфиденциальность·© 2026 Kitploit

Каталог инструментов

Категории

Все категории
Loading categories
dploot — Loot and decrypt Windows DPAPI secrets remotely or offline, including masterkeys, credentials, vaults, certificates, browser data, and cached Azure tokens. | Kitploit
Инструменты/GitHubGitHub/zblurx/dploot
Encryption/Decryption ToolsPost-ExploitationDigital ForensicsPenetration TestingCloud SecurityRed Teaming
GitHubzblurx/dploot

dploot

Loot and decrypt Windows DPAPI secrets remotely or offline, including masterkeys, credentials, vaults, certificates, browser data, and cached Azure tokens.

Репозиторий
555751715 дней назадПроверено Kitploit

Популярное

Смотреть все →

Откройте для себя самые используемые инструменты нашего сообщества.

Изучить все инструменты

Просмотрите нашу коллекцию инструментов

Смотреть все инструменты →
Поделиться
Контент недоступен на запрошенном языке. Показываем английскую версию.

dploot

dploot is Python rewrite of SharpDPAPI written in C# by Harmj0y, which is itself a port of DPAPI from Mimikatz by gentilkiwi. It implements all the DPAPI logic of these tools, but this time it is usable with a python interpreter and from a Linux environment.

If you don't know what is DPAPI, check out this post.

Table of Contents

  • dploot
    • Table of Contents
    • Installation
    • Usage
      • Protocols
      • Kerberos
    • How to use
      • Remote access via SMB
      • Remote access via WMI
      • Remote access via WinRM
      • Remote access via MSSQL
      • Local filesystem access
      • Remote access via Cobalt Strike
      • As a domain administrator
      • As a non-domain administrator
    • Commands
      • User Triage
        • masterkeys
        • credentials
        • vaults
        • rdg
        • certificates
        • browser
        • cng
        • wam
        • mobaxterm
        • triage
      • Machine Triage
        • machinemasterkeys
        • machinecredentials
        • machinevaults
        • machinecertificates
        • machinecng
        • machinetriage
      • Misc
        • wifi
        • sccm
        • backupkey
        • blob
    • Credits

Installation

You can install dploot directly from PyPI with pipx:

pipx install git+https://github.com/zblurx/dploot.git

OR

pipx install dploot

On Kali Linux, you can install dploot from the repositories:

sudo apt install python3-dploot

Usage

dploot (https://github.com/zblurx/dploot) v4.0.0 by @_zblurx
usage: dploot [-h]
              {backupkey,blob,browser,certificates,cng,credentials,machinecertificates,machinecng,machinecredentials,machinemasterkeys,machinetriage,machinevaults,masterkeys,mobaxterm,rdg,sccm,triage,vaults,wam,wifi}
              ...

DPAPI looting in Python

positional arguments:
  {backupkey,blob,browser,certificates,cng,credentials,machinecertificates,machinecng,machinecredentials,machinemasterkeys,machinetriage,machinevaults,masterkeys,mobaxterm,rdg,sccm,triage,vaults,wam,wifi}
                        Action
    backupkey           Backup Keys from domain controller
    blob                Decrypt DPAPI blob. Can fetch masterkeys on target
    browser             Dump users credentials and cookies saved in browser from local or remote target
    certificates        Dump users certificates from local or remote target
    cng                 Dump users CNG files blob from local or remote target
    credentials         Dump users Credential Manager blob from local or remote target
    machinecertificates
                        Dump system certificates from local or remote target
    machinecng          Dump system CNG files from local or remote target
    machinecredentials  Dump system credentials from local or remote target
    machinemasterkeys   Dump system masterkey from local or remote target
    machinetriage       Loot SYSTEM Masterkeys (if not set), SYSTEM credentials, SYSTEM certificates and SYSTEM vaults from local or remote target
    machinevaults       Dump system vaults from local or remote target
    masterkeys          Dump users masterkey from local or remote target
    mobaxterm           Dump Passwords and Credentials from MobaXterm
    rdg                 Dump users saved password information for RDCMan.settings from local or remote target
    sccm                Dump SCCM secrets (NAA, Collection variables, tasks sequences credentials) from local or remote target
    triage              Loot Masterkeys (if not set), credentials, rdg, certificates, browser and vaults from local or remote target
    vaults              Dump users Vaults blob from local or remote target
    wam                 Dump users cached azure tokens from local or remote target
    wifi                Dump wifi profiles from local or remote target

options:
  -h, --help            show this help message and exit

Protocols

dploot v4.0.0+ supports multiple network protocols for remote access. You select the protocol using --protocol <protocol_name>. Each protocol has different capabilities and requirements:

  • smb (default): Uses SMB/RPC for remote file access and registry operations. Works with most Windows targets. Supports Kerberos authentication. Works with impacket
  • wmi: Uses Windows Management Instrumentation (DCOM) for remote execution and registry operations. Useful alternative to SMB. Supports Kerberos authentication. Works with impacket
  • winrm: Uses Windows Remote Management for PowerShell-based operations. Common in modern environments. Works with pypsrp
  • mssql: Connects via MSSQL Server. Supports both domain and local database authentication. Supports Kerberos authentication. Works with impacket
  • local: Accesses a mounted or copied Windows filesystem directly (no network connection needed). Useful for offline analysis of physical drives or disk images.
  • cobaltstrike: Executes operations through a Cobalt Strike beacon REST API. Useful for red team operations with Cobalt Strike infrastructure.

Example using WMI protocol:

$ dploot masterkeys --protocol wmi -d waza.local -u Administrator -p 'Password!123' -t 192.168.57.5

Example using local protocol (offline filesystem):

$ dploot masterkeys --protocol local --root /mnt/c_drive -u bob -p Password

Important notes on command support:

  • Most commands support all protocols. However, backupkey only works with SMB protocol (requires domain controller access).
  • Only smb protocol supports LSA dump to automaticaly dump the DPAPI machine key. For the other protocols, you will have to bring it by yourself with --dpapi-system-key.

Kerberos

dploot can authenticate with Kerberos for the smb, wmi, and mssql protocols. Use -k to enable Kerberos with NTLM fallback. If you want to use a cached ticket, use --use-kcache. To use an AES key, use --aesKey.

$ dploot masterkeys -d waza.local -u Administrator -k -t 192.168.57.5

How to use

The goal of dploot is to simplify DPAPI related loot from a Linux box. How you use this tool depends on your access level and target configuration.

Remote access via SMB

The default protocol is SMB. This is the most common approach for DPAPI looting and works with standard Windows file sharing:

$ dploot masterkeys -d waza.local -u Administrator -p 'Password!123' -t 192.168.57.5
[*] Connected to 192.168.57.5 as waza.local\Administrator (admin)

[*] Triage ALL USERS masterkeys

{d305b55b-f0ca-40cf-b04c-3620aa5da427}:6f45f9ee77014df8a68104abd0e8d5eadb3d9f22
{d37fa151-d670-4c58-9d70-3233b4918942}:8709574524ad35ef0b3a114b93990f8490d86cba

Remote access via WMI

WMI provides an alternative to SMB for remote access and is useful when SMB is restricted:

Скачать инструмент