Credential Access
KeeThief
Extract KeePass keys and entries from memory.
credentialswindows
keethief — terminal
$ Get-KeePassDatabaseKey # PowerShellWhat it does
KeeThief pulls KeePass master-key material from a running process and can decrypt database entries. Useful when a target relies on KeePass for secret storage.
Source
https://github.com/HarmJ0y/KeeThief ↗More Credential Access tools
Need hosted scanning instead of local tooling?
Run a scan in the browser →