python-dpapick-0.3-0.noarch.rpm


Advertisement

Description

python-dpapick - DPAPI decryption toolkit

Property Value
Distribution Fedora 29
Repository CERT Forensics Tools x86_64
Package filename python-dpapick-0.3-0.noarch.rpm
Package name python-dpapick
Package version 0.3
Package release 0
Package architecture noarch
Package type rpm
Category Development/Languages/Python
Homepage http://www.dpapick.com
License GPL-3.0
Maintainer -
Download size 67.30 KB
Installed size 255.90 KB
OVERVIEW
DPAPIck is a python toolkit to provide a platform-independant implementation
of Microsoft's cryptography subsytem called DPAPI (Data Protection API).
It can be used either as a library or as a standalone tool.
It is also the first open-source tool that allows decryption of DPAPI
structures in an offline way and, moreover, from another plateform than
Windows.
It is provided with some application probes that includes the built-in logic
to retreive the corresponding secrets that are protected.
To have more information or to contact us, go to our website:
http://www.dpapick.com
REQUIREMENTS
This application has been developped and tested on python 2.7.
M2Crypto is required to provide all the requireds algorithms. To obtain it,
see: http://chandlerproject.org/bin/view/Projects/MeTooCrypto
Probes and other tool may require other modules to be able to retreive
information such as:
* python-sqlite3 for Google Chrome password database
* CFPropertyList for Apple Safari keychain.plist
see https://github.com/bencochran/CFPropertyList
* python-registry for low-level manipulation of hives
see https://github.com/williballenthin/python-registry
* pyASN1 for the RSA key pair manipulation
see http://pyasn1.sourceforge.net/
We also recommend the use of MoonSols Windows Memory Toolkit to convert
hibernation file to usable memory dumps and be able to extract credentials
from it.
For more information about Moonsols products, see <http://www.moonsols.com>
AUTHOR
DPAPIck is written by Jean-Michel Picod (jean-michel.picod@cassidian.com)
with the help from Ivan Fontarensky (ivan.fontarensky@cassidian.com)
who work for the Cyber Security Center of Cassidian, an EADS company,
and Elie Bursztein (dpapi@elie.im)
LICENSE
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation version 3 of the License.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with this program.  If not, see <http://www.gnu.org/licenses/>.

Alternatives

Package Version Architecture Repository
python-dpapick-0.3-0.noarch.rpm 0.3 noarch CERT Forensics Tools
python-dpapick - - -

Requires

Name Value
/usr/bin/python2 -
python(abi) = 2.7

Provides

Name Value
python-dpapick = 0.3-0
python2.7dist(dpapick) = 0.3
python2dist(dpapick) = 0.3

Download

Type URL
Mirror forensics.cert.org
Binary Package python-dpapick-0.3-0.noarch.rpm
Source Package python-dpapick-0.3-0.src.rpm

Install Howto

  1. Download cert-forensics-tools-release-29 rpm:
    https://forensics.cert.org/cert-forensics-tools-release-29.rpm
  2. Install cert-forensics-tools-release-29 rpm:
    # rpm -Uvh cert-forensics-tools-release*rpm
  3. Install python-dpapick rpm package:
    # dnf --enablerepo=forensics install python-dpapick

Files

Path
/usr/bin/dpapidec
/usr/lib/python2.7/site-packages/DPAPI/__init__.py
/usr/lib/python2.7/site-packages/DPAPI/__init__.pyc
/usr/lib/python2.7/site-packages/DPAPI/__init__.pyo
/usr/lib/python2.7/site-packages/DPAPI/probe.py
/usr/lib/python2.7/site-packages/DPAPI/probe.pyc
/usr/lib/python2.7/site-packages/DPAPI/probe.pyo
/usr/lib/python2.7/site-packages/DPAPI/Core/__init__.py
/usr/lib/python2.7/site-packages/DPAPI/Core/__init__.pyc
/usr/lib/python2.7/site-packages/DPAPI/Core/__init__.pyo
/usr/lib/python2.7/site-packages/DPAPI/Core/blob.py
/usr/lib/python2.7/site-packages/DPAPI/Core/blob.pyc
/usr/lib/python2.7/site-packages/DPAPI/Core/blob.pyo
/usr/lib/python2.7/site-packages/DPAPI/Core/credhist.py
/usr/lib/python2.7/site-packages/DPAPI/Core/credhist.pyc
/usr/lib/python2.7/site-packages/DPAPI/Core/credhist.pyo
/usr/lib/python2.7/site-packages/DPAPI/Core/crypto.py
/usr/lib/python2.7/site-packages/DPAPI/Core/crypto.pyc
/usr/lib/python2.7/site-packages/DPAPI/Core/crypto.pyo
/usr/lib/python2.7/site-packages/DPAPI/Core/eater.py
/usr/lib/python2.7/site-packages/DPAPI/Core/eater.pyc
/usr/lib/python2.7/site-packages/DPAPI/Core/eater.pyo
/usr/lib/python2.7/site-packages/DPAPI/Core/masterkey.py
/usr/lib/python2.7/site-packages/DPAPI/Core/masterkey.pyc
/usr/lib/python2.7/site-packages/DPAPI/Core/masterkey.pyo
/usr/lib/python2.7/site-packages/DPAPI/Core/registry.py
/usr/lib/python2.7/site-packages/DPAPI/Core/registry.pyc
/usr/lib/python2.7/site-packages/DPAPI/Core/registry.pyo
/usr/lib/python2.7/site-packages/DPAPI/Probes/IE7.py
/usr/lib/python2.7/site-packages/DPAPI/Probes/IE7.pyc
/usr/lib/python2.7/site-packages/DPAPI/Probes/IE7.pyo
/usr/lib/python2.7/site-packages/DPAPI/Probes/RDP.py
/usr/lib/python2.7/site-packages/DPAPI/Probes/RDP.pyc
/usr/lib/python2.7/site-packages/DPAPI/Probes/RDP.pyo
/usr/lib/python2.7/site-packages/DPAPI/Probes/__init__.py
/usr/lib/python2.7/site-packages/DPAPI/Probes/__init__.pyc
/usr/lib/python2.7/site-packages/DPAPI/Probes/__init__.pyo
/usr/lib/python2.7/site-packages/DPAPI/Probes/certificate.py
/usr/lib/python2.7/site-packages/DPAPI/Probes/certificate.pyc
/usr/lib/python2.7/site-packages/DPAPI/Probes/certificate.pyo
/usr/lib/python2.7/site-packages/DPAPI/Probes/chrome.py
/usr/lib/python2.7/site-packages/DPAPI/Probes/chrome.pyc
/usr/lib/python2.7/site-packages/DPAPI/Probes/chrome.pyo
/usr/lib/python2.7/site-packages/DPAPI/Probes/credstore.py
/usr/lib/python2.7/site-packages/DPAPI/Probes/credstore.pyc
/usr/lib/python2.7/site-packages/DPAPI/Probes/credstore.pyo
/usr/lib/python2.7/site-packages/DPAPI/Probes/dropbox.py
/usr/lib/python2.7/site-packages/DPAPI/Probes/dropbox.pyc
/usr/lib/python2.7/site-packages/DPAPI/Probes/dropbox.pyo
/usr/lib/python2.7/site-packages/DPAPI/Probes/gtalk.py
/usr/lib/python2.7/site-packages/DPAPI/Probes/gtalk.pyc
/usr/lib/python2.7/site-packages/DPAPI/Probes/gtalk.pyo
/usr/lib/python2.7/site-packages/DPAPI/Probes/icloud.py
/usr/lib/python2.7/site-packages/DPAPI/Probes/icloud.pyc
/usr/lib/python2.7/site-packages/DPAPI/Probes/icloud.pyo
/usr/lib/python2.7/site-packages/DPAPI/Probes/safari.py
/usr/lib/python2.7/site-packages/DPAPI/Probes/safari.pyc
/usr/lib/python2.7/site-packages/DPAPI/Probes/safari.pyo
/usr/lib/python2.7/site-packages/DPAPI/Probes/skype.py
/usr/lib/python2.7/site-packages/DPAPI/Probes/skype.pyc
/usr/lib/python2.7/site-packages/DPAPI/Probes/skype.pyo
/usr/lib/python2.7/site-packages/DPAPI/Probes/wifi.py
/usr/lib/python2.7/site-packages/DPAPI/Probes/wifi.pyc
/usr/lib/python2.7/site-packages/DPAPI/Probes/wifi.pyo
/usr/lib/python2.7/site-packages/dpapick-0.3-py2.7.egg-info/PKG-INFO
/usr/lib/python2.7/site-packages/dpapick-0.3-py2.7.egg-info/SOURCES.txt
/usr/lib/python2.7/site-packages/dpapick-0.3-py2.7.egg-info/dependency_links.txt
/usr/lib/python2.7/site-packages/dpapick-0.3-py2.7.egg-info/not-zip-safe
/usr/lib/python2.7/site-packages/dpapick-0.3-py2.7.egg-info/requires.txt
/usr/lib/python2.7/site-packages/dpapick-0.3-py2.7.egg-info/top_level.txt

See Also

Package Description
python-haystack-0.42-1.fc29.noarch.rpm Search C Structures in a process' memory
python-ioc_writer-0.3.3-0.noarch.rpm API providing a limited CRUD for manipulating OpenIOC formatted Indicators of Compromise
python-pycoin-0.77-0.noarch.rpm Utilities for Bitcoin and altcoin addresses and transaction manipulation
python-registry-1.2.0-1.fc29.x86_64.rpm Read access to Windows Registry Files
python2-artifacts-20190320-2.fc29.x86_64.rpm ForensicArtifacts.com Artifact Repository
python2-bencode-2.1.0-1.fc29.noarch.rpm Simple bencode parser for Python 2
python2-biplist-1.0.3-3.fc29.x86_64.rpm biplist is a library for reading/writing binary plists
python2-certifi-2019.9.11-1.fc29.noarch.rpm %{sum}
python2-construct-2.5.2-4.fc29.noarch.rpm A powerful declarative parser/builder for binary data
python2-dfdatetime-20190517-2.fc29.noarch.rpm Digital Forensics date and time (dfDateTime)
python2-dfvfs-20190714-1.fc29.noarch.rpm Digital Forensics Virtual File System (dfVFS)
python2-dfwinreg-20190714-1.fc29.x86_64.rpm Digital Forensics Windows Registry (dfWinReg)
python2-dtfabric-20190120-3.fc29.x86_64.rpm Data type fabric (dtfabric)
python2-elasticsearch-7.0.5-1.fc29.x86_64.rpm Python client for Elasticsearch
python2-pefile-2019.4.18-2.fc29.noarch.rpm Python module for working with Portable Executable files
Advertisement
Advertisement