New DPAPISnoop Tool Enables Extraction of CREDHIST Hashes From Windows Systems
ID: ebc66f51-0012-5560-8154-1ca8fa5a42de
STIX ID: report--ebc66f51-0012-5560-8154-1ca8fa5a42de
Feed Name: GBHackers
Researchers enhanced the open-source DPAPISnoop tool to parse Windows DPAPI CREDHIST files and extract historical credential material into offline-crackable hash formats, enabling attackers or red teams to use Hashcat (new modes 15920 and 15930) to recover previous passwords. The technique leverages intended DPAPI functionality and filesystem access to user profiles, highlights differences in cryptographic strength across legacy and modern entries, and urges monitoring of %APPDATA%\Microsoft\Protect\CREDHIST and related DPAPI directories while refining detection rules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
