DPAPI Demystified: Abusing the Windows Data Protection API one secret at a time

Description

The Data Protection API (DPAPI) is a critical yet often overlooked component of Windows security. It provides transparent data encryption services to both users and applications, enabling the secure storage of sensitive information such as credentials, encryption keys, and browser data. This talk demystifies how DPAPI works and should give an idea about the basics as well as the gotchas.

Daniel Küppers

Senior Penetration Tester @ CODE WHITE GmbH