🔐
AutomationPython

Abusing DPAPI for Credential Access

by mukul975

Abusing DPAPI for Credential Access is an Automation skill for Claude Code, published by mukul975 in Anthropic-Cybersecurity-Skills.

27.8K stars3.4K forkson mukul975/Anthropic-Cybersecurity-SkillsAdded 2026/08/14Repository updated 2026/08/08
ai-agentsclaude-codecloud-securitycybersecuritydevsecopsethical-hackingincident-responseinfosecllmmalware-analysismcpmitre-attacknist-csfosintpenetration-testingred-teamsecuritysecurity-automationthreat-huntingthreat-intelligence
Install in seconds
Install Abusing DPAPI for Credential Access
Copy Abusing DPAPI for Credential Access into your Claude Code skills folder. Run the command in your terminal, or review the source on GitHub before installing.
terminal
npx degit https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/abusing-dpapi-for-credential-access ~/.claude/skills/abusing-dpapi-for-credential-access

Requires Node.js. Downloads this skill only — not the rest of the repository — into your Claude Code skills folder.

Without Node.js

git clone https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git

Clones the whole repository, then copy the skill’s own directory into your skills folder yourself.

In this catalog

Source file
skills/abusing-dpapi-for-credential-access/SKILL.md in mukul975/Anthropic-Cybersecurity-Skills
Installs to
~/.claude/skills/abusing-dpapi-for-credential-access
Collection
One of 25 skills cataloged from this repository
Category
Automation1523 skills

What Abusing DPAPI for Credential Access does

Abusing DPAPI for Credential Access extracts and decrypts Windows DPAPI-protected secrets using SharpDPAPI, Mimikatz, or Impacket. Use it during authorized red-team engagements after gaining a foothold or when triaging DPAPI blobs.

Abusing DPAPI for Credential Access is cataloged under Automation on DirSkills. Abusing DPAPI for Credential Access comes from a repository tagged ai-agents, claude-code, cloud-security, cybersecurity and devsecops.

Documentation

README

Abusing DPAPI for Credential Access

Legal Notice: This skill is for authorized penetration testing, red-team engagements, and educational purposes only. Extracting credentials from systems you do not own or lack explicit written authorization to test is illegal and may violate computer fraud and abuse laws. Always operate within a signed rules-of-engagement and document every action.

Overview

This is the opening of the README. Read the full README on GitHub.

Commands Abusing DPAPI for Credential Access provides

Slash commands named in this skill’s SKILL.md, listed in the order they first appear.

  • /unprotect
  • /showall

Frequently asked about Abusing DPAPI for Credential Access

  • What else does mukul975 publish alongside Abusing DPAPI for Credential Access?

    Abusing DPAPI for Credential Access is one of 25 skills that DirSkills catalogs from mukul975/Anthropic-Cybersecurity-Skills, the repository it ships in. Its siblings there include API Gateway Log Analysis, Achieving CMMC Level 2 Compliance and Add New Skill. Each one is a separate skill with its own page in this directory, installs the same way Abusing DPAPI for Credential Access does, and is maintained by mukul975 in that same repository. The rest of the collection is listed on the mukul975/Anthropic-Cybersecurity-Skills page.

  • How does Abusing DPAPI for Credential Access compare to other Automation skills?

    Abusing DPAPI for Credential Access ranks #102 by stars among the 1523 Automation skills in this catalog. The most-starred ones next to it are Autonomous Loops, Autonomous Agent Harness and Automation Audit Ops. DirSkills ranks by the star count of the repository each skill ships in, so that order reflects how popular those repositories are rather than any review of Abusing DPAPI for Credential Access against them. Open each page to compare what they document and how they install.

More from mukul975/Anthropic-Cybersecurity-Skills

Abusing DPAPI for Credential Access is one of 25 skills cataloged on DirSkills from mukul975/Anthropic-Cybersecurity-Skills.

See all 25 skills
🛡️
2w ago

API Gateway Log Analysis

API Gateway Log Analysis parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect attack patterns such as BOLA, excessive data exposure, and injection attempts. Use it when investigating security incidents or building detection rules.
Data
27.8K3.4K
🛡️
2w ago

Achieving CMMC Level 2 Compliance

Achieving CMMC Level 2 Compliance guides defense contractors through scoping CUI and FCI, implementing the 110 NIST SP 800-171 controls, computing the SPRS score, and preparing for a C3PAO assessment. Use it when handling CUI under DoD contracts or responding to DFARS 7012/7019/7020/7021 requirements.
Quality
27.8K3.4K
🛡️
2w ago

Add New Skill

Add New Skill provides a structured template for creating cybersecurity-focused Claude Code skills aligned with MITRE ATT&CK and NIST CSF. Use it when documenting a new security capability for the agent.
AI Engineering
27.8K3.4K
🛡️
2w ago

Analyzing APT Group with MITRE Navigator

Analyzing APT Group with MITRE Navigator queries ATT&CK data with attackcti, mitreattack-python, and stix2, then builds Navigator layers and heatmap overlays to compare APT group TTPs, identify detection gaps, and report threat intelligence.
Data
27.8K3.4K
🛡️
2w ago

Analyzing Active Directory ACL Abuse

Analyzing Active Directory ACL Abuse connects to a domain controller via ldap3 to parse security descriptors and detect dangerous ACL misconfigurations that enable attacks like privilege escalation.
DevOps
27.8K3.4K
🔍
2w ago

Analyzing Android Malware with Apktool

Analyzing Android Malware with Apktool performs static analysis of Android APK files using apktool, jadx, and androguard to extract permissions, detect dangerous permission combinations, and identify suspicious API calls without executing the sample. Use it to triage a suspicious APK or build mobile malware detection rules.
Quality
27.8K3.4K