backupkeys
Last updated
Last updated
lsadump::backupkeys
dumps the DPAPI backup keys from the Domain Controller (cf. ). By holding the backup keys any user's master key can be decrypted and as a result the users' secrets can be decrypted. It has the following command line arguments:
/export
: export the output as .pvk
which means "private key"
/secret
: at the time of writing, November 1st 2021, we don't know what this option refers to
/system
: the target DC hostname
/guid
: The szGuid
value. It can be found at C:\Users\<username>\AppData\Roaming\Microsoft\Credentials
, C:\Users\<username>\AppData\Local\Microsoft\Credentials
and C:\Users\<username>\AppData\Roaming\Microsoft\Protect\SID
. It can also be obtained with
This command requires elevated privileges (by previously running or by executing Mimikatz as the NT-AUTHORITY\SYSTEM
account).