protect
dpapi::protect protects data via a DPAPI call. It has the following command line arguments:
  • /c: displays the output as a C programming language char array
  • /out: save the results to a file
  • /data: the data to encrypt
  • /system: the data are encrypted under the system account context. It will be visible in the flags : system
  • /prompt: the Mimikatz's additional DPAPI prompt GUI
  • /entropy: the entropy for the encryption
  • /machine: The data are encrypted under the machine account context. It will be visible in the flags : local_machine
  • /description: provide a description for the blob data
It must be noted that during our tests when using the /system parameter, even running Mimikatz with token::elevate, the following error was raised
1
mimikatz # dpapi::protect /data:"Hello Mimikatz" /system
2
data : Hello Mimikatz description : flags : system ; prompt flags: entropy :
3
ERROR kuhl_m_dpapi_protect ; CryptProtectData (0x00000057)
Copied!
Searching on Google the error code displayed this link​
1
mimikatz # dpapi::protect /data:"Hello Mimikatz"
2
​
3
data : Hello Mimikatz
4
description :
5
flags :
6
prompt flags:
7
entropy :
8
​
9
**BLOB**
10
dwVersion : 00000001 - 1
11
guidProvider : {df9d8cd0-1501-11d1-8c7a-00c04fc297eb}
12
dwMasterKeyVersion : 00000001 - 1
13
guidMasterKey : {5c22983f-77ee-41e4-9086-8073d664e417}
14
dwFlags : 00000000 - 0 ()
15
dwDescriptionLen : 00000002 - 2
16
szDescription :
17
algCrypt : 00006603 - 26115 (CALG_3DES)
18
dwAlgCryptLen : 000000c0 - 192
19
dwSaltLen : 00000010 - 16
20
pbSalt : a912cfd0a5981bd1176cfa3a46f613e9
21
dwHmacKeyLen : 00000000 - 0
22
pbHmackKey :
23
algHash : 00008004 - 32772 (CALG_SHA1)
24
dwAlgHashLen : 000000a0 - 160
25
dwHmac2KeyLen : 00000010 - 16
26
pbHmack2Key : 8966a81153fbeecaa0f27257870c4d64
27
dwDataLen : 00000020 - 32
28
pbData : a61e42e1f1e13c06e9f45f1f813ecb8f91967195018745caf774f910e9bdf2cb
29
dwSignLen : 00000014 - 20
30
pbSign : 585b4a5b91aab83f82438508a082258af88296bb
31
​
32
​
33
Blob:
34
01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0
35
4f c2 97 eb 01 00 00 00 3f 98 22 5c ee 77 e4 41
36
90 86 80 73 d6 64 e4 17 00 00 00 00 02 00 00 00
37
00 00 03 66 00 00 c0 00 00 00 10 00 00 00 a9 12
38
cf d0 a5 98 1b d1 17 6c fa 3a 46 f6 13 e9 00 00
39
00 00 04 80 00 00 a0 00 00 00 10 00 00 00 89 66
40
a8 11 53 fb ee ca a0 f2 72 57 87 0c 4d 64 20 00
41
00 00 a6 1e 42 e1 f1 e1 3c 06 e9 f4 5f 1f 81 3e
42
cb 8f 91 96 71 95 01 87 45 ca f7 74 f9 10 e9 bd
43
f2 cb 14 00 00 00 58 5b 4a 5b 91 aa b8 3f 82 43
44
85 08 a0 82 25 8a f8 82 96 bb
Copied!
Example output with the /c parameter:
1
mimikatz # dpapi::protect /data:"Hello Mimikatz" /c
2
​
3
data : Hello Mimikatz
4
description :
5
flags :
6
prompt flags:
7
entropy :
8
​
9
**BLOB**
10
dwVersion : 00000001 - 1
11
guidProvider : {df9d8cd0-1501-11d1-8c7a-00c04fc297eb}
12
dwMasterKeyVersion : 00000001 - 1
13
guidMasterKey : {5c22983f-77ee-41e4-9086-8073d664e417}
14
dwFlags : 00000000 - 0 ()
15
dwDescriptionLen : 00000002 - 2
16
szDescription :
17
algCrypt : 00006603 - 26115 (CALG_3DES)
18
dwAlgCryptLen : 000000c0 - 192
19
dwSaltLen : 00000010 - 16
20
pbSalt : a58805a047af3d5c5c728e0cd99ea2e6
21
dwHmacKeyLen : 00000000 - 0
22
pbHmackKey :
23
algHash : 00008004 - 32772 (CALG_SHA1)
24
dwAlgHashLen : 000000a0 - 160
25
dwHmac2KeyLen : 00000010 - 16
26
pbHmack2Key : 974bf2f32c5558d572b55c4342fb7d0b
27
dwDataLen : 00000020 - 32
28
pbData : 518d8d9f26507a869139c7a40f20c5cac4e90664e51961ff11df0cf5ccab0b67
29
dwSignLen : 00000014 - 20
30
pbSign : 5fd6a45422ed0bc317f71dc627bdb49fabe0f911
31
​
32
​
33
Blob:
34
​
35
BYTE data[] = {
36
0x01, 0x00, 0x00, 0x00, 0xd0, 0x8c, 0x9d, 0xdf, 0x01, 0x15, 0xd1, 0x11, 0x8c, 0x7a, 0x00, 0xc0,
37
0x4f, 0xc2, 0x97, 0xeb, 0x01, 0x00, 0x00, 0x00, 0x3f, 0x98, 0x22, 0x5c, 0xee, 0x77, 0xe4, 0x41,
38
0x90, 0x86, 0x80, 0x73, 0xd6, 0x64, 0xe4, 0x17, 0x00, 0x00, 0x00, 0x00, 0x02, 0x00, 0x00, 0x00,
39
0x00, 0x00, 0x03, 0x66, 0x00, 0x00, 0xc0, 0x00, 0x00, 0x00, 0x10, 0x00, 0x00, 0x00, 0xa5, 0x88,
40
0x05, 0xa0, 0x47, 0xaf, 0x3d, 0x5c, 0x5c, 0x72, 0x8e, 0x0c, 0xd9, 0x9e, 0xa2, 0xe6, 0x00, 0x00,
41
0x00, 0x00, 0x04, 0x80, 0x00, 0x00, 0xa0, 0x00, 0x00, 0x00, 0x10, 0x00, 0x00, 0x00, 0x97, 0x4b,
42
0xf2, 0xf3, 0x2c, 0x55, 0x58, 0xd5, 0x72, 0xb5, 0x5c, 0x43, 0x42, 0xfb, 0x7d, 0x0b, 0x20, 0x00,
43
0x00, 0x00, 0x51, 0x8d, 0x8d, 0x9f, 0x26, 0x50, 0x7a, 0x86, 0x91, 0x39, 0xc7, 0xa4, 0x0f, 0x20,
44
0xc5, 0xca, 0xc4, 0xe9, 0x06, 0x64, 0xe5, 0x19, 0x61, 0xff, 0x11, 0xdf, 0x0c, 0xf5, 0xcc, 0xab,
45
0x0b, 0x67, 0x14, 0x00, 0x00, 0x00, 0x5f, 0xd6, 0xa4, 0x54, 0x22, 0xed, 0x0b, 0xc3, 0x17, 0xf7,
46
0x1d, 0xc6, 0x27, 0xbd, 0xb4, 0x9f, 0xab, 0xe0, 0xf9, 0x11,
47
};
Copied!
Save the blob results to a file:
1
mimikatz # dpapi::protect /data:"Hello Mimikatz" /out:dpapi_blob.txt
2
​
3
data : Hello Mimikatz
4
description :
5
flags :
6
prompt flags:
7
entropy :
8
​
9
**BLOB**
10
dwVersion : 00000001 - 1
11
guidProvider : {df9d8cd0-1501-11d1-8c7a-00c04fc297eb}
12
dwMasterKeyVersion : 00000001 - 1
13
guidMasterKey : {5c22983f-77ee-41e4-9086-8073d664e417}
14
dwFlags : 00000000 - 0 ()
15
dwDescriptionLen : 00000002 - 2
16
szDescription :
17
algCrypt : 00006603 - 26115 (CALG_3DES)
18
dwAlgCryptLen : 000000c0 - 192
19
dwSaltLen : 00000010 - 16
20
pbSalt : 091527cbb82555872260774bd8d3ff28
21
dwHmacKeyLen : 00000000 - 0
22
pbHmackKey :
23
algHash : 00008004 - 32772 (CALG_SHA1)
24
dwAlgHashLen : 000000a0 - 160
25
dwHmac2KeyLen : 00000010 - 16
26
pbHmack2Key : ab94cd34e247f59647a4872f0ab8e647
27
dwDataLen : 00000020 - 32
28
pbData : a5e9d57d114c39374caec5983d2aa80c942d77c080f4ec7569cfb58a00357e2e
29
dwSignLen : 00000014 - 20
30
pbSign : 05ba3324d8ef8b44ef474f6ad1cf73ba1b08e58e
31
​
32
​
33
Write to file 'dpapi_blob.txt' is OK
Copied!
The following picture demonstrates an example when the /prompt argument is used:
DPAPI Prompt
Last modified 6mo ago
Copy link