DonPAPI-Collect
NEWDonPAPI (login-securite) mass-harvests DPAPI-protected secrets across a set of Windows hosts from Linux without dropping a binary: it remotely reads and decrypts credential blobs, saved browser passwords and cookies, Wi-Fi keys, scheduled task and vault credentials, and certificates. The collect subcommand takes standard NetExec-style auth (-u/-p, -H for hashes, -k/--aesKey for Kerberos) and a -t target list; --fetch-pvk grabs the domain backup key so user masterkeys decrypt automatically. Results land in a local database browsable afterward with donpapi gui. Requires local admin on each target and is loud at scale, so scope the target list carefully. Command Reference: Target IP: 10.10.10.1 Domain: test.local Username: john Password: password123