logo

Reverse engineering and decrypting CyberArk vault credential files

ID: d0c97cb8-70a2-5a27-9bca-98fd577c1168

STIX ID: report--d0c97cb8-70a2-5a27-9bca-98fd577c1168

Feed Name: Fox-IT blog

Threat Score
70/100

Date Published: 2021-10-12

Date Updated: 2026-04-27

Author: Fox It

...
...

This technical analysis demonstrates that CyberArk password-type .cred files use a recoverable custom key-derivation and AES encryption scheme based primarily on an AdditionalInformation field; the author reverse-engineered the algorithm, implemented a Python decryption tool, and recommends protecting credential files and using DPAPI protection—CyberArk subsequently released an update to mitigate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.