Editorial and source context
What this Skill does
Abusing Dpapi For Credential Access is a source-indexed Agent Skill for automation & integrations work. Based on the SKILL.md description, it focuses on extract and decrypt windows dpapi-protected secrets (credential manager, browser logins/cookies, wi-fi…. Use the linked GitHub file to confirm scope and prerequisites before enabling it.
What the author says
Extract and decrypt Windows DPAPI-protected secrets (Credential Manager, browser logins/cookies, Wi-Fi credentials, KeePass keys) online or offline using SharpDPAPI, SharpChrome, Mimikatz, or Impacket's dpapi.py, including domain-wide decryption via the DPAPI backup key. Use during authorized red-team credential-access engagements after gaining a foothold or when triaging DPAPI blobs pulled from a host.
Compatibility and requirements
- Use an agent runtime that supports Agent Skills and the linked SKILL.md format.
- Confirm the source repository's tools, SDKs, and platform prerequisites for api design work.
How to install or import it
- Open the linked GitHub SKILL.md and review its scope and setup instructions.
- Install or import the skill using the agent runtime's documented workflow.
- Run a small, non-sensitive test and verify the output before broader use.
Permissions and risks
- Review every command, file path, network request, dependency, and credential scope before enabling it.
- GitHub stars indicate popularity, not safety or correctness; validate the source and test with non-sensitive data.
Example workflows
- Ask an AI agent to apply Abusing Dpapi For Credential Access to api design work described in the source record.
- Have the agent state assumptions, required tools, and expected output before using this automation & integrations skill.
- Compare the result with the linked GitHub SKILL.md and verify it against your project requirements.
Related Agent Skills
More source records in Automation & Integrations.