Тёмный

Decrypt EFS protected files by recreating the missing user certificate 

Simpan
Подписаться 7
Просмотров 298
50% 1

If you have encrypted windows files from a previous user, these certificates needs to be recreated for your new user so you can unlock the files. For this method to work you need to have access to the /Users/ folder from your previous installation, along with the password or the NTLM hash.
Tools used: mimikatz and git bash (for openssl)
Steps:
00:00 Introduction and prerequisites
00:40 #1. Find out which certificate is needed for the encrypted file
02:30 #2. Download mimikatz
03:25 #3. Export the certificate to .DER
04:20 #4. Locate the private certificate
06:19 #5. Find and decrypt the masterkey for private certificate
09:17 #6. Decrypt the private certificate using masterkey hash
10:24 #7. Create the PFX certificate using openssl
13:40 #8. Install the new certificate
Tags:
#efs #bitlocker #certificate #pvk #der #pem #protected #decrypt #encrypt #files #windows #private #public #locked #access #mimikatz #cmd #rsa #crypto #microsoft #publickey #privatekey #masterkey #hash #ntlm #user #win10 #certutil #openssl #cipher

Опубликовано:

 

4 окт 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 13   
@Kolodia
@Kolodia 2 месяца назад
You are my lifesaver. I struggled on password part but I made it. Thanks mate
@Simpan_TV
@Simpan_TV 2 месяца назад
Glad to hear it was working for you!
@icarus33
@icarus33 4 месяца назад
Damn, what a great video! Mine didn't work first try. But then I installed the certificate by double clicking it, then it worked!
@Simpan_TV
@Simpan_TV 4 месяца назад
Happy to hear you had use of the video! My head was thinking too deep into commands so I didnt think of the fact you could just double click it.
@mathabapilusa278
@mathabapilusa278 Месяц назад
Hi @simpan_TV , PLEASE ASSIST BRO,🙏🙏 similar situation but copied users files from user account on c driver, then installed new windows on user computer only for the copied files to be encrypted, nothing works to decrypt. And unfortunately backup other than the copied user files which are encrypted don't exist. Is it possible to recover or decrypt user data. Please please help 🙏🙏🙏, I'm about to be fired at work over this incident as our company doesn't allow losing user data
@saileshnakum9287
@saileshnakum9287 2 месяца назад
Certificate lost after new windows install how to😢
@Simpan_TV
@Simpan_TV 2 месяца назад
You need to have a backup of the old files. If you just format the disk its still possible it might be in the unused sectors and is able to be restored.
@saileshnakum9287
@saileshnakum9287 2 месяца назад
How to restore​@@Simpan_TV
@mathabapilusa278
@mathabapilusa278 Месяц назад
Hi @simpan_TV , PLEASE ASSIST BRO,🙏🙏 similar situation but copied users files from user account on c driver, then installed new windows on user computer only for the copied files to be encrypted, nothing works to decrypt. And unfortunately backup other than the copied user files which are encrypted don't exist. Is it possible to recover or decrypt user data. Please please help 🙏🙏🙏, I'm about to be fired at work over this incident as our company doesn't allow losing user data
@mathabapilusa278
@mathabapilusa278 Месяц назад
Hi @simpan_TV , PLEASE ASSIST BRO,🙏🙏 similar situation but copied users files from user account on c driver, then installed new windows on user computer only for the copied files to be encrypted, nothing works to decrypt. And unfortunately backup other than the copied user files which are encrypted don't exist. Is it possible to recover or decrypt user data. Please please help 🙏🙏🙏, I'm about to be fired at work over this incident as our company doesn't allow losing user data
@saileshnakum9287
@saileshnakum9287 2 месяца назад
Any other solution?
@Simpan_TV
@Simpan_TV 2 месяца назад
Afraid no other solution is known to my knowledge
@mathabapilusa278
@mathabapilusa278 Месяц назад
Hi @simpan_TV , PLEASE ASSIST BRO,🙏🙏 similar situation but copied users files from user account on c driver, then installed new windows on user computer only for the copied files to be encrypted, nothing works to decrypt. And unfortunately backup other than the copied user files which are encrypted don't exist. Is it possible to recover or decrypt user data. Please please help 🙏🙏🙏, I'm about to be fired at work over this incident as our company doesn't allow losing user data
Далее
NTFS Explained - EFS Encryption - How it works?
15:46
Просмотров 2,2 тыс.
Why Are Open Source Alternatives So Bad?
13:06
Просмотров 645 тыс.
КОТЯТА НАУЧИЛИСЬ ГОВОРИТЬ#cat
00:13
Why I don't change SSH from port 22
13:31
Просмотров 31 тыс.
How to Get $500 Motherboards for $50
31:29
Просмотров 1,3 млн
The cloud is over-engineered and overpriced (no music)
14:39
How A Steam Bug Deleted Someone’s Entire PC
11:49
Become a shell wizard in ~12 mins
12:25
Просмотров 251 тыс.
When I accidentally ran ransomware!
7:57
Просмотров 170 тыс.
CrowdStrike IT Outage Explained by a Windows Developer
13:40
Creating Games With ChatGPT
49:03
Просмотров 152