独立于偏移量的凭据提取工具
DeadMatter 是一款用 C# 编写的专用工具,旨在从内存转储中提取敏感信息,例如活动登录会话的密码哈希。它采用雕刻(carving)技术从各种文件类型中检索凭据,例如原始或 minidump 格式的进程或完整内存转储、解压缩的休眠文件、虚拟机内存文件,或其他可能包含登录凭据的文件类型。
该工具对渗透测试人员、红队成员和取证调查人员特别有用,因为它有助于分析系统安全漏洞并辅助数字取证调查。DeadMatter 在渗透测试人员和红队成员的攻防演练中非常有用,因为他们经常需要应对 EDR 和 AV 软件检测和/或阻止其以 minidump 格式转储 LSASS 进程内存的尝试。转储并外泄完整内存转储的替代方案通常不可行。因此,DeadMatter 应运而生,以填补这一空白,让攻击团队能够直接在受害机器上解析内存转储文件,从而当场提取 NTLM 哈希、DPAPI 密钥和其他有用信息。
该工具已在 Black Hat USA 2025 Arsenal 上展示。
Extract credentials from a full memory dump file in raw format using both Mimikatz structure and carving techniques
--------------------------------------------------------------------------------------------------------------
C:\> Deadmatter.exe -f memory_dump.raw
Extract credentials from a full memory dump file in raw format using carving techniques only
---------------------------------------------------------------------------------------
C:\> Deadmatter.exe -f memory_dump.raw -m carve
Identify the OS version based on the MSV structure details
----------------------------------------------------------
C:\> Deadmatter.exe -f memory_dump.raw -m none -i
Extract credentials from a minidump file using Windows 10 version 1507 Mimikatz structure technique with verbose output
----------------------------------------------------------------------------------------------------------------------
C:\> Deadmatter.exe -f lsass.dmp -m mimikatz -w WIN_10_1507 -v
Extract credentials and DPAPI keys from a full memory dump file in raw format and brute-force search for the IV
----------------------------------------------------------------------------------------------------------------------
C:\> Deadmatter.exe -f memory_dump.raw -b -d
特别感谢 cube0x0,因为 DeadMatter 大量基于 MiniDump 的代码
特别感谢 theodoros997 搭建测试基础设施以及他的 Google Chrome 解密工具
感谢以下人员的项目与出色工作,没有他们,我们自己的项目就不可能实现。
DeadMatter 按“原样”提供,不附带任何保证。它仅供合格的信息安全专业人员在授权的渗透测试、红队攻防演练或取证调查中使用。DeadMatter 和 QSecure 的开发者对工具的滥用或使用该工具进行的任何非法或恶意活动不承担任何责任或义务。