KeePass
MITRE ATT&CK™ Credentials from Password Stores: Password Managers - Technique T1555.005
Theory
Practice
Enumeration
# Search by files
python3 KeePwn.py search -u <ADMIN_ACCOUNT> -p <PASSWORD> -d <DOMAIN> -tf ./targets.txt
# Search by processes + csv output
python3 KeePwn.py search -u <ADMIN_ACCOUNT> -p <PASSWORD> -d <DOMAIN> -tf ./targets.txt --threads 4 --get-process --found-only --output keepwn_out.csvnxc smb <TARGETS> -u <ADMIN_ACCOUNT> -p <PASSWORD> -M keepass_discoverKeePass Plugin Abuse
KeePass Trigger Abuse - CVE-2023-24055
Cracking KDBX Database Master Password
Extract Passphrase from Memory - CVE-2023-32784
KeePass DLL Injection
Resources
Last updated