Reading DPAPI Encrypted Secrets with Mimikatz and C++
Overview
Reading Chrome Cookies and Login Data
dpapi::chrome /in:"%localappdata%\Google\Chrome\User Data\Default\Cookies"

Protecting and Unprotecting Data


Decrypting Other User's Secrets



Retrieving MasterKey with User's Password

Extracting DPAPI Backup Keys with Domain Admin



Using DPAPIs to Encrypt / Decrypt Data in C++
CryptProtectData


CryptUnprotectData

Decrypting Remote Desktop Connection Manager Passwords from .rdg





References
Last updated