DPAPI Demystified - Abusing The Windows Data Protection API One Secret At A Time
BSidesMunich via YouTube
Launch Your Cybersecurity Career in 6 Months
Power BI Fundamentals - Create visualizations and dashboards from scratch
Overview
Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Explore the Windows Data Protection API (DPAPI) in this 31-minute conference talk that demystifies how this critical Windows security mechanism works and reveals methods for exploiting it. Learn about DPAPI's architecture, understand how Windows uses it to protect sensitive data like passwords and encryption keys, and discover techniques for extracting and abusing stored secrets. Examine real-world attack scenarios where adversaries can leverage DPAPI weaknesses to access protected information, analyze the security implications of DPAPI implementation flaws, and understand defensive strategies to mitigate these risks. Gain practical insights into how attackers can systematically compromise DPAPI-protected data and develop a deeper understanding of Windows credential storage mechanisms for both offensive and defensive security purposes.
Syllabus
DPAPI Demystified: Abusing The Windows Data Protection API One Secret At A Time - Daniel Küppers
Taught by
BSidesMunich