Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Microsoft Site Warning: Certificate Expiry Causes Issues
June 15, 2026
SHADOWBYT3$ Claims Nintendo Breach, Sensitive Data
June 15, 2026
DPAPISnoop Tool Recovers Windows Credentials Offline via
June 15, 2026
Home/CyberSecurity News/DPAPISnoop Tool Recovers Windows Credentials Offline via
CyberSecurity News

DPAPISnoop Tool Recovers Windows Credentials Offline via

The open-source DPAPISnoop tool has been enhanced, now extracting CREDHIST entries. This significant update enables the offline cracking of historical Windows credentials and provides deeper insight...

Emy Elsamnoudy
Emy Elsamnoudy
June 15, 2026 3 Min Read
1 0

The open-source DPAPISnoop tool has been enhanced, now extracting CREDHIST entries. This significant update enables the offline cracking of historical Windows credentials and provides deeper insight into password patterns. Lefteris Panos, Security Consultant at LRQA Red Team, confirmed the enhancement specifically adds CREDHIST extraction capabilities to DPAPISnoop. It also facilitates the recovery and analysis of historical Windows credentials alongside DPAPI Master Key hashes.

Microsoft’s Data Protection API (DPAPI) is widely used to protect sensitive user data such as browser credentials, encryption keys, and stored secrets.

Traditionally, attackers and red teamers focus on recovering DPAPI Master Keys, which allow the decryption of protected data. However, another lesser-explored artifact, CREDHIST, plays a critical role in DPAPI’s design.

DPAPISnoop Tool Extracts

When a user changes their password, Windows maintains a chain of previous password-derived keys to ensure older encrypted data remains accessible.

Access to a user's CREDHIST entries ( source : lrqa )
Access to a user’s CREDHIST entries ( source : lrqa )

This credential history is stored in the CREDHIST file located under: %APPDATA%MicrosoftProtect.

Each entry in the file represents a previous password, encrypted using key material derived from that password, forming a sequential chain.

According to Lefteris Panos at LRQA Red Team, the updated DPAPISnoop tool can parse CREDHIST files and convert entries into offline-crackable hash formats.

These hashes, identified by the “$credhist$” prefix, can be used directly with Hashcat.

To support this, researchers introduced two new Hashcat modes:

1. 15920 for CREDHIST entries using 3DES with HMAC-SHA1.

2. 15930 for entries using AES-256 with SHA-512.

This allows attackers or testers to brute-force historical password entries independently, without needing to decrypt the entire DPAPI key upfront.

Once hashes are extracted, they can be cracked offline using GPU-based tools like Hashcat. If a password is recovered, it can be fed back into DPAPISnoop to decrypt additional entries in the chain.

For example, cracking a mid-chain CREDHIST entry reveals the SHA1 or NTLM hash of an older password, which can then be used to unlock further entries. This iterative process allows reconstruction of a user’s password history.

The tool outputs a hash that can be cracked offline( source : lrqa )
The tool outputs a hash that can be cracked offline ( source : lrqa )

Notably, older entries often use weaker cryptographic schemes, such as SHA1-based PBKDF2 with 3DES, making them significantly easier to crack than modern SHA-512 implementations with higher iteration counts.

While this behavior is not a vulnerability, it highlights how legitimate Windows features can be leveraged to obtain credentials when attackers gain filesystem access.

The ability to recover historical passwords provides valuable intelligence, including: Identification of password reuse patterns. Insight into password complexity trends. Potential reuse across enterprise systems.

This can significantly accelerate lateral movement and privilege escalation in real-world attacks.

Detection and Mitigation

Defenders should monitor for abnormal access to DPAPI-related paths, particularly:

%APPDATA%MicrosoftProtectCREDHIST. User-specific DPAPI directories. Remote access via SMB or administrative shares.

Security tools such as Sigma and Elastic already provide detection rules for suspicious access to credential history files.

The key challenge is distinguishing normal DPAPI activity from anomalous file access patterns.

Organizations are advised to enforce strong password policies, limit local file access, and monitor endpoint activity for unusual credential-related behavior.

The research by Lefteris Panos highlights how revisiting well-known mechanisms like DPAPI can still uncover new offensive opportunities, reinforcing the importance of continuous research in Windows credential security.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackSecurityVulnerability

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Critical Microsoft 365 Copilot Flaw Vulnerability Allows

Next Post

SHADOWBYT3$ Claims Nintendo Breach, Sensitive Data

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Hackers Use Microsoft Graph Reconnaissance to Target Payroll and
June 15, 2026
China-Nexus Hackers Exploit PAM Modules Backdoored Credential
June 15, 2026
SearchJack: 23 Chrome Extensions Hijack Campaign Uses
June 15, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us