[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fArB9ghSBzcfstQdVJoT6RnQ6siLxvWXNAgWm-lpUeZA":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":30,"aiConfidence":30,"updatedAt":49,"createdAt":49,"_status":48},527,"What are the key differences in data structures and offsets when implementing sekurlsa::wdigest across different Windows versions?","The main differences involve the offsets for IV, DES, and AES keys in lsasrv.dll, and the structure of the BCRYPT_KEY used for decryption—Win7 uses `KIWI_BCRYPT_KEY`, while Windows 8 and 10 use `KIWI_BCRYPT_KEY81`. The AES and 3DES decryption keys are stored inside a `KIWI_HARD_KEY` structure, with `cbSecret` indicating the length. These version-specific offsets are detailed in the Mimikatz source and the [Implementation of sekurlsa::wdigest in Mimikatz](\u002Fnews\u002Fimplementation-of-sekurlsa-wdigest-in-mimikatz) article.","\u003Cp>The main differences involve the offsets for IV, DES, and AES keys in lsasrv.dll, and the structure of the BCRYPT_KEY used for decryption—Win7 uses `KIWI_BCRYPT_KEY`, while Windows 8 and 10 use `KIWI_BCRYPT_KEY81`. The AES and 3DES decryption keys are stored inside a `KIWI_HARD_KEY` structure, with `cbSecret` indicating the length. These version-specific offsets are detailed in the Mimikatz source and the [Implementation of sekurlsa::wdigest in Mimikatz](\u002Fnews\u002Fimplementation-of-sekurlsa-wdigest-in-mimikatz) article.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fimplementation-of-sekurlsa-wdigest-in-mimikatz\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-are-the-key-differences-in-data-structures-and-offsets-when-implementing-se-1777483339149","data structures, offsets, KIWI_BCRYPT_KEY, Windows versions, decryption",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":19,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":39,"qaPairs":40,"meta":45,"updatedAt":46,"createdAt":47,"_status":48},130,"Implementation of sekurlsa::wdigest in Mimikatz","implementation-of-sekurlsa-wdigest-in-mimikatz","Learn how to implement Mimikatz's sekurlsa::wdigest module to extract plaintext passwords from lsass across Windows versions, including Win7 to Win10.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The sekurlsa::wdigest module in Mimikatz is a frequently used feature in penetration testing. It can extract credentials from the lsass process, typically obtaining plaintext passwords of logged-in users (by default, this is not possible on Windows Server 2008 R2 and later systems; registry modifications are required, and the user must log in again to obtain them).\u003C\u002Fp>\u003Cp>XPN documented his research insights on WDigest in his blog and open-sourced a POC, implementing credential extraction from the lsass process on Win10_1809 x64 using C++.\u003C\u002Fp>\u003Cp>This article will extend XPN's POC to support Win7\u002FWin8\u002FWindows Server 2008\u002FWindows Server 2008 R2\u002FWindows Server 2012\u002FWindows Server 2012 R2, detailing the implementation process and specifics.\u003C\u002Fp>\u003Cp>XPN's blog:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblog.xpnsec.com\u002Fexploring-mimikatz-part-1\u002F\u003C\u002Fp>\u003Cp>POC:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002Fxpn\u002F12a6907a2fce97296428221b3bd3b394\u003C\u002Fp>\u003Ch2>0x02 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Implementation approach\u003C\u002Fli>\u003Cli>Program implementation details\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 Implementation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Col>\u003Cli>Elevate to Debug Privileges\u003C\u002Fli>\u003Cli>Obtain lsass Process Handle\u003C\u002Fli>\u003Cli>Enumerate handles of all modules in the lsass process, locate the memory positions of wdigest.dll and lsasrv.dll\u003C\u002Fli>\u003Cli>Retrieve InitializationVector, AES, and 3DES values from lsasrv.dll for decryption\u003C\u002Fli>\u003Cli>Extract credential information from wdigest.dll, determine encryption algorithm, and decrypt to obtain plaintext passwords\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Detailed explanation is as follows:\u003C\u002Fp>\u003Ch3>1. Elevate to Debug Privileges\u003C\u002Fh3>\u003Cp>Code can directly reuse previous code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch3>2. Obtain lsass Process Handle\u003C\u002Fh3>\u003Cul>\u003Cli>Create a process snapshot via CreateToolhelp32Snapshot\u003C\u002Fli>\u003Cli>Traverse the process list\u003C\u002Fli>\u003Cli>Search for the lsass.exe process and obtain its pid\u003C\u002Fli>\u003Cli>Obtain lsass process handle\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>3. Enumerate handles of all modules in the lsass process, locate the memory positions of wdigest.dll and lsasrv.dll\u003C\u002Fh3>\u003Cp>Enumerate handles of all modules in the lsass process via EnumProcessModules\u003C\u002Fp>\u003Ch3>4. Retrieve InitializationVector, AES, and 3DES values from lsasrv.dll for decryption\u003C\u002Fh3>\u003Cp>Offset positions vary across different systems; refer to mimikatz source code for details:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgentilkiwi\u002Fmimikatz\u002Fblob\u002F68ac65b426d1b9e1354dd0365676b1ead15022de\u002Fmimikatz\u002Fmodules\u002Fsekurlsa\u002Fcrypto\u002Fkuhl_m_sekurlsa_nt6.c#L8-L32\u003C\u002Fp>\u003Cp>The following four offsets differ:\u003C\u002Fp>\u003Cul>\u003Cli>LsaInitializeProtectedMemory_KEY\u003C\u002Fli>\u003Cli>int IV_OFFSET\u003C\u002Fli>\u003Cli>int DES_OFFSET\u003C\u002Fli>\u003Cli>int AES_OFFSET\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The data structures for AES and 3DES also vary across different systems:\u003C\u002Fp>\u003Cp>Win7:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>typedef struct _KIWI_BCRYPT_KEY {\u003Cbr>\tULONG size;\u003Cbr>\tULONG tag;\t\u002F\u002F 'MSSK'\u003Cbr>\tULONG type;\u003Cbr>\tULONG unk0;\u003Cbr>\tULONG unk1;\u003Cbr>\tULONG bits;\u003Cbr>\tKIWI_HARD_KEY hardkey;\u003Cbr>} KIWI_BCRYPT_KEY, *PKIWI_BCRYPT_KEY;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Source:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgentilkiwi\u002Fmimikatz\u002Fblob\u002Fmaster\u002Fmodules\u002Fkull_m_crypto.h#L56\u003C\u002Fp>\u003Cp>Windows 8 and Windows 10:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>typedef struct _KIWI_BCRYPT_KEY81 {\u003Cbr>\tULONG size;\u003Cbr>\tULONG tag;\t\u002F\u002F 'MSSK'\u003Cbr>\tULONG type;\u003Cbr>\tULONG unk0;\u003Cbr>\tULONG unk1;\u003Cbr>\tULONG unk2; \u003Cbr>\tULONG unk3;\u003Cbr>\tULONG unk4;\u003Cbr>\tPVOID unk5;\t\u002F\u002F before, align in x64\u003Cbr>\tULONG unk6;\u003Cbr>\tULONG unk7;\u003Cbr>\tULONG unk8;\u003Cbr>\tULONG unk9;\u003Cbr>\tKIWI_HARD_KEY hardkey;\u003Cbr>} KIWI_BCRYPT_KEY81, *PKIWI_BCRYPT_KEY81;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Source:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgentilkiwi\u002Fmimikatz\u002Fblob\u002Fmaster\u002Fmimikatz\u002Fmodules\u002Fsekurlsa\u002Fcrypto\u002Fkuhl_m_sekurlsa_nt6.h#L22\u003C\u002Fp>\u003Cp>Among them, KIWI_HARD_KEY in KIWI_BCRYPT_KEY and KIWI_BCRYPT_KEY81 stores AES and 3DES data, with the following structure:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>typedef struct _KIWI_HARD_KEY {\u003Cbr>\tULONG cbSecret;\u003Cbr>\tBYTE data[ANYSIZE_ARRAY]; \u002F\u002F etc...\u003Cbr>} KIWI_HARD_KEY, *PKIWI_HARD_KEY;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Source:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgentilkiwi\u002Fmimikatz\u002Fblob\u002Fmaster\u002Fmodules\u002Fkull_m_crypto.h#L51\u003C\u002Fp>\u003Cp>ULONG cbSecret indicates the length, BYTE data[ANYSIZE_ARRAY] is the actual encrypted content\u003C\u002Fp>\u003Ch3>5. Obtain credential information from wdigest.dll and decrypt the plaintext password\u003C\u002Fh3>\u003Cp>Credential information is located at a fixed offset and can be located by searching for a fixed structure (BYTE PTRN_WIN6_PasswdSet[]\t= {0x48, 0x3b, 0xd9, 0x74};)\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Source:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgentilkiwi\u002Fmimikatz\u002Fblob\u002Fmaster\u002Fmimikatz\u002Fmodules\u002Fsekurlsa\u002Fpackages\u002Fkuhl_m_sekurlsa_wdigest.c#L14\u003C\u002Fp>\u003Cp>Each credential is stored in a doubly linked list format, as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>typedef struct _KIWI_WDIGEST_LIST_ENTRY {\u003Cbr>\tstruct _KIWI_WDIGEST_LIST_ENTRY *Flink;\u003Cbr>\tstruct _KIWI_WDIGEST_LIST_ENTRY *Blink;\u003Cbr>\tULONG\tUsageCount;\u003Cbr>\tstruct _KIWI_WDIGEST_LIST_ENTRY *This;\u003Cbr>\tLUID LocallyUniqueIdentifier;\u003Cbr>} KIWI_WDIGEST_LIST_ENTRY, *PKIWI_WDIGEST_LIST_ENTRY;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Source:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgentilkiwi\u002Fmimikatz\u002Fblob\u002Fmaster\u002Fmimikatz\u002Fmodules\u002Fsekurlsa\u002Fpackages\u002Fkuhl_m_sekurlsa_wdigest.h#L14\u003C\u002Fp>\u003Cp>Credential information is stored at offset 48 of each node, with the following format:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>typedef struct _KIWI_GENERIC_PRIMARY_CREDENTIAL\u003Cbr>{\u003Cbr>\tLSA_UNICODE_STRING UserName;\u003Cbr>\tLSA_UNICODE_STRING Domaine;\u003Cbr>\tLSA_UNICODE_STRING Password;\u003Cbr>} KIWI_GENERIC_PRIMARY_CREDENTIAL, *PKIWI_GENERIC_PRIMARY_CREDENTIAL;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Source:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgentilkiwi\u002Fmimikatz\u002Fblob\u002Fmaster\u002Fmimikatz\u002Fmodules\u002Fsekurlsa\u002Fglobals_sekurlsa.h#L36\u003C\u002Fp>\u003Cp>Each credential selects an algorithm based on the length of the encrypted data:\u003C\u002Fp>\u003Cul>\u003Cli>If the length of the encrypted data is a multiple of 8, AES is used in CFB mode.\u003C\u002Fli>\u003Cli>Otherwise, 3DES is used in CBC mode.\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x04 Program Implementation Details\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>XPN's POC supports extracting credentials from the lsass process on Win10_1809 x64, address as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002Fxpn\u002F12a6907a2fce97296428221b3bd3b394\u003C\u002Fp>\u003Cp>To make it support Win7\u002FWin8\u002FWindows Server 2008\u002FWindows Server 2008 R2\u002FWindows Server 2012\u002FWindows Server 2012 R2, the following issues need to be considered:\u003C\u002Fp>\u003Ch3>1. Add code to elevate to Debug privilege\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>BOOL EnableDebugPrivilege(BOOL fEnable)\u003Cbr>{\u003Cbr>\tBOOL fOk = FALSE;\u003Cbr>\tHANDLE hToken;\u003Cbr>\tif (OpenProcessToken(GetCurrentProcess(), TOKEN_ADJUST_PRIVILEGES, &amp;hToken))\u003Cbr>\t{\u003Cbr>\t\tTOKEN_PRIVILEGES tp;\u003Cbr>\t\ttp.PrivilegeCount = 1;\u003Cbr>\t\tLookupPrivilegeValue(NULL, SE_DEBUG_NAME, &amp;tp.Privileges[0].Luid);\u003Cbr>\t\ttp.Privileges[0].Attributes = fEnable ? SE_PRIVILEGE_ENABLED : 0;\u003Cbr>\t\tAdjustTokenPrivileges(hToken, FALSE, &amp;tp, sizeof(tp), NULL, NULL);\u003Cbr>\t\tfOk = (GetLastError() == ERROR_SUCCESS);\u003Cbr>\t\tCloseHandle(hToken);\u003Cbr>\t}\u003Cbr>\treturn(fOk);\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Determine the operating system version\u003C\u002Fh3>\u003Cp>The previous code can be used here, with the address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>It should be noted that the code does not specifically determine the exact version of Win10, and different Win10 systems have different offsets, for example, Win10_1507 and Win10_1903\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Source:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgentilkiwi\u002Fmimikatz\u002Fblob\u002Fmaster\u002Fmimikatz\u002Fmodules\u002Fsekurlsa\u002Fcrypto\u002Fkuhl_m_sekurlsa_nt6.c#L21-L22\u003C\u002Fp>\u003Ch3>3. Different operating system versions correspond to different offsets\u003C\u002Fh3>\u003Cp>Affects the following four parameters:\u003C\u002Fp>\u003Cul>\u003Cli>LsaInitializeProtectedMemory_KEY\u003C\u002Fli>\u003Cli>int IV_OFFSET\u003C\u002Fli>\u003Cli>int DES_OFFSET\u003C\u002Fli>\u003Cli>int AES_OFFSET\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>4. Different operating system versions correspond to different AES and 3DES data structures\u003C\u002Fh3>\u003Cp>Win7:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>KIWI_BCRYPT_KEY extracted3DesKey, extractedAesKey;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Windows 8 and Windows 10:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>KIWI_BCRYPT_KEY81 extracted3DesKey, extractedAesKey;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>5. Determine the length of encrypted data in each credential\u003C\u002Fh3>\u003Cp>Use different decryption algorithms and reflect this in the output:\u003C\u002Fp>\u003Cul>\u003Cli>If the encrypted data length is a multiple of 8, use AES in CFB mode\u003C\u002Fli>\u003Cli>Otherwise, use 3DES in CBC mode\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The complete code has been open-sourced at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements credential reading for 64-bit systems, with output identical to mimikatz's sekurlsa::wdigest results, supporting the following operating systems:\u003C\u002Fp>\u003Cul>\u003Cli>Windows 7 x64\u002FWindows Server 2008 x64\u002FWindows Server 2008 R2 x64\u003C\u002Fli>\u003Cli>Windows 8 x64\u002FWindows Server 2012 x64\u002FWindows Server 2012 R2 x64\u003C\u002Fli>\u003Cli>Windows 10 1507 (and before 1903) x64\u003C\u002Fli>\u003C\u002Ful>\u003Cp>To support Windows 10 1903, add identification for Windows 10 1903 and later versions, along with corresponding offset calculations\u003C\u002Fp>\u003Cp>To support 32-bit systems, modify the offsets of corresponding variables\u003C\u002Fp>\u003Ch2>0x05 Supplement\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>For systems running Windows Server 2008 R2 and later, plaintext information cannot be stored in credentials under default configurations, thus preventing the export of plaintext passwords. This issue can be resolved by modifying the registry to enable Wdigest Auth, as follows:\u003C\u002Fp>\u003Cp>cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add HKLM\\SYSTEM\\CurrentControlSet\\Control\\SecurityProviders\\WDigest \u002Fv UseLogonCredential \u002Ft REG_DWORD \u002Fd 1 \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>or powershell:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Set-ItemProperty -Path HKLM:\\SYSTEM\\CurrentControlSet\\Control\\SecurityProviders\\WDigest -Name UseLogonCredential -Type DWORD -Value 1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After the user logs in again, plaintext information in the credentials can be obtained.\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article extends XPN's POC to support Win7\u002FWin8\u002FWindows Server 2008\u002FWindows Server 2008 R2\u002FWindows Server 2012\u002FWindows Server 2012 R2,\u003C\u002Fp>\u003Cp>implementing the functionality of Mimikatz's sekurlsa::wdigest, and documenting the details and process of the program implementation.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",5,"published","2026-02-02T07:51:00.064Z",{"title":36,"description":14,"keywords":37,"ogImage":30,"canonicalUrl":30,"noIndex":38},"Mimikatz WDigest Credential Extraction: Implementation & Decryption Guide","Mimikatz, WDigest, credential extraction, lsass, penetration testing, Windows security, password decryption, sekurlsa, POC, XPN",false,[],{"docs":41,"hasNextPage":38},[42,4,43,44],528,526,525,{"title":30,"description":30,"image":30},"2026-07-24T02:07:23.025Z","2026-07-23T16:01:41.508Z","draft","2026-07-23T16:13:02.539Z"]