Security & Threat Intelligence · 25.07.2026, 15:29 UTC
Offensive DPAPI With Nemesis
| Schweregrad | info |
|---|---|
| Kategorie | Security & Threat Intelligence |
| Quelle | SpecterOps ↗ |
| Veröffentlicht | 25.07.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
TL;DR: Nemesis 2.2 automates the entire DPAPI decryption chain – from SYSTEM/user masterkeys through CNG keys to Chromium’s latest App-Bound Encryption – with robust forward as well as retroactive decryption.
The Windows Data Protection API, or DPAPI, is the fun little technology that just won’t disappear from offensive operations. I first talked about abusing DPAPI on operations in my 2018 post Operational Guidance for Offensive User DPAPI Abuse. Some things have changed since then, but plenty stayed the same. SpecterOps has touched on using DPAPI in specific use cases over the last several years, from Slack, to capturing custom entropy, and even how it factors into protections for certificates and CA private keys, but the major systems and tool(s) we used for abuse didn’t majorly change until Nemesis 1.0.0 (and then with my colleague Andrew Gomez’ cookie-monster project for Chrome v1.37+).
During our recent Nemesis 2.2 development sprint, we turned our eyes to DPAPI yet again and heavily revamped how we use and abuse DPAPI. This post will summarize the major new DPAPI features, how everything works internally, and will give you everything you need to get started analyzing and abusing DPAPI in Nemesis!
Nemesis Is a Cookie Monster
Note: What we’re talking about here will not touch on TPM usage. We’re handling purely file and memory based approaches.
Another note: In case it isn’t obvious, DPAPI applies to only Windows, so while there is some overlap in how Chrome/Chromium protects secrets on other platforms like macOS. We’re only going to focus on the Windows side of …
Maßnahmen
⬇ Als MarkdownVerwandte Beiträge
- info Spline rebuilt its entire 3D editor. Then it handed the keys to Claude Code.
- info USN-8669-1: Linux kernel (NVIDIA) vulnerabilities
- info ContestTrade: A Multi-Agent Trading System Based on Internal Contest Mechanism
- info DeepConvContext: A Multi-Scale Approach to Timeseries Classification in Human Activity Recognition