Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
DeadMatter — 独立于偏移量的凭据提取工具 | Kitploit
工具/GitHubGitHub/qsecure-labs/deadmatter
密码破解内存取证哈希分析取证分析后渗透利用数据恢复恶意软件分析数字取证渗透测试红队
GitHubqsecure-labs/deadmatter

DeadMatter

6910241年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

独立于偏移量的凭据提取工具

查看仓库

DeadMatter

Version License Black Hat Arsenal 2025 GitHub stars

DeadMatter 是一款用 C# 编写的专用工具,旨在从内存转储中提取敏感信息,例如活动登录会话的密码哈希。它采用雕刻(carving)技术从各种文件类型中检索凭据,例如原始或 minidump 格式的进程或完整内存转储、解压缩的休眠文件、虚拟机内存文件,或其他可能包含登录凭据的文件类型。

该工具对渗透测试人员、红队成员和取证调查人员特别有用,因为它有助于分析系统安全漏洞并辅助数字取证调查。DeadMatter 在渗透测试人员和红队成员的攻防演练中非常有用,因为他们经常需要应对 EDR 和 AV 软件检测和/或阻止其以 minidump 格式转储 LSASS 进程内存的尝试。转储并外泄完整内存转储的替代方案通常不可行。因此,DeadMatter 应运而生,以填补这一空白,让攻击团队能够直接在受害机器上解析内存转储文件,从而当场提取 NTLM 哈希、DPAPI 密钥和其他有用信息。

该工具已在 Black Hat USA 2025 Arsenal 上展示。

用法

root@kitploit:~
Extract credentials from a full memory dump file in raw format using both Mimikatz structure and carving techniques
--------------------------------------------------------------------------------------------------------------
C:\> Deadmatter.exe -f memory_dump.raw


Extract credentials from a full memory dump file in raw format using carving techniques only
---------------------------------------------------------------------------------------
C:\> Deadmatter.exe -f memory_dump.raw -m carve


Identify the OS version based on the MSV structure details
----------------------------------------------------------
C:\> Deadmatter.exe -f memory_dump.raw -m none -i


Extract credentials from a minidump file using Windows 10 version 1507 Mimikatz structure technique with verbose output
----------------------------------------------------------------------------------------------------------------------
C:\> Deadmatter.exe -f lsass.dmp -m mimikatz -w WIN_10_1507 -v


Extract credentials and DPAPI keys from a full memory dump file in raw format and brute-force search for the IV
----------------------------------------------------------------------------------------------------------------------
C:\> Deadmatter.exe -f memory_dump.raw -b -d

支持的凭据

  • Msv
  • Dpapi

待办事项

  • SAM(即将推出)
  • Kerberos 票据
  • 安全问题
  • Bitlocker 密钥
  • 缓存凭据
  • WDigest 凭据
  • 从 STDIN 处理文件

致谢

特别感谢 cube0x0,因为 DeadMatter 大量基于 MiniDump 的代码

特别感谢 theodoros997 搭建测试基础设施以及他的 Google Chrome 解密工具

感谢以下人员的项目与出色工作,没有他们,我们自己的项目就不可能实现。

  • pypykatz,作者 skelsec
  • mimikatz,作者 gentilkiwi
  • sharpkatz,作者 b4rtik

免责声明

DeadMatter 按“原样”提供,不附带任何保证。它仅供合格的信息安全专业人员在授权的渗透测试、红队攻防演练或取证调查中使用。DeadMatter 和 QSecure 的开发者对工具的滥用或使用该工具进行的任何非法或恶意活动不承担任何责任或义务。

下载工具