KeePass
Enumerate DB locations:
KeePassXC
Extract Passphrase from Memory
DLL Hijacking
Extract Passphrase from Memory (< v2.53.1)
CVE-2023-32784
Abusing KeePass Triggers (< v2.54)
Tools
KeeFarce
KeeFarceReborn
Abusing the KeePass Plugin Cache
Export DB by compiling and loading a malicious plugin (requires admin's privileges to place the .plgx
file):
Export DB by hijacking a legit plugin DLL (requires an existent plugin in use):
KeePassHax
KeeThief
CrackMapExec
KeePwn
ThievingFox
Last updated