login-securite / DonPAPI

Dumping DPAPI credz remotely
GNU General Public License v3.0
930 stars 110 forks source link

Enhancement: Retrieve Token Broker Cache Files #72

Open Cyb3rC3lt opened 3 months ago

Cyb3rC3lt commented 3 months ago

Hi there,

I wonder would you consider an enhancement to retrieve the Azure token broker cache files from their folder and potentially decrypt them? We could then laterally move to Azure potentially.

I think it would be an amazing feature. More info on where they are located here:

https://blog.xpnsec.com/wam-bam/