Tuesday, September 29, 2026

Inside DeadMatter: carving NTLM hashes and DPAPI keys out of raw memory without fixed offsets

Inside DeadMatter: carving NTLM hashes and DPAPI keys out of raw memory without fixed offsets

DeadMatter is a C# credential-carving tool that pulls NTLM hashes and DPAPI keys from raw, minidump, hibernation, or VM memory images during authorized engagements and forensic investigations.

Toolqsecure-labs/DeadMatter — offset-independent credential extraction from memory dumps in C#
CategoryMemory forensics / credential carving (offensive + DFIR)
Primary UseParsing full or minidump memory images on-site to recover NTLM hashes and DPAPI keys without relying on version-specific LSASS offsets
Safe UseIntended solely for qualified professionals during authorized penetration tests, red team engagements, and forensic investigations, per the project's own disclaimer
Telemetry NoteRuns entirely offline against local files; from a defensive view, its activity appears as process execution and file reads of .raw/.dmp images on the analyzed host, and recovered hashes should be treated as compromised

DeadMatter, published by qsecure-labs under a BSD-3-Clause license, is a C# tool whose stated purpose is the extraction of sensitive material — principally password hashes belonging to active logon sessions — from memory images. What distinguishes it from the crowded field of LSASS parsing utilities is its explicit design goal of offset independence. Rather than hardcoding per-build structure offsets the way mimikatz-style tooling traditionally does, DeadMatter leans on carving techniques to locate and interpret credential structures inside arbitrary memory content, which makes it resilient across Windows versions and patch levels.

The README is candid about the operational gap the tool fills. Offense teams increasingly face EDR and AV products that detect or block attempts to dump LSASS into a classic minidump, and exfiltrating a full raw memory image is frequently impractical at engagement scale. DeadMatter's answer is to run on the target itself and parse memory dump files locally, extracting NTLM hashes and DPAPI keys in place. That is a meaningful architectural choice: instead of moving a large, noisy dump across the wire, only the small parsed artifacts leave the machine.

Input flexibility is the other headline trait. The tool accepts process dumps and full memory dumps in raw or minidump format, decompressed hibernation files, virtual machine memory files, and, more generally, any file that might plausibly contain logon credential material. For forensic investigators this breadth matters: an image acquired for incident response can be fed in without prior conversion, and the carving mode can operate when the structured LSASS minidump scaffolding is absent or damaged.

Internally, DeadMatter exposes multiple extraction strategies through its -m flag. The mimikatz mode reuses the well-understood structure-parsing approach popularized by mimikatz and reimplemented in projects like pypykatz and sharpkatz, and can be pinned to a specific build — the README shows -w WIN_10_1507 — when the analyst knows the source OS. The carve mode is the interesting one: it locates credential structures by pattern rather than by offset table, which is what allows the tool to work on raw full-memory images where no minidump directory exists.

The usage examples in the README also reveal two supporting capabilities worth noting. The -i flag performs OS identification by inspecting MSV structure details, letting the operator fingerprint the memory image before committing to a parsing strategy. The -b flag enables a brute-force search for the initialization vector used in decrypting LSASS-protected secret blobs, paired with -d for DPAPI key extraction — a reminder that credential material in memory is routinely encrypted at rest within the process and must be decrypted before it is useful.

Current credential coverage is deliberately narrow: the supported list names only Msv and Dpapi. That is less than pypykatz or mimikatz offer today, but the roadmap section shows the intended trajectory — SAM extraction marked as coming soon, plus Kerberos tickets, security questions, BitLocker keys, cached credentials, WDigest credentials, and the ability to read a process dump from STDIN. The roadmap reads like a checklist of everything a post-exploitation analyst expects from a mature LSASS parser, and version 0.9.5_Beta makes clear the project is honest about not being there yet.

The lineage is transparent and, in this ecosystem, a positive signal. The authors credit cube0x0's MiniDump as the codebase DeadMatter is heavily based on, and acknowledge skelsec (pypykatz), gentilkiwi (mimikatz), and b4rtik (sharpkatz) as foundations. For anyone auditing the tool before use — which you should do with anything that touches credentials — this gives a clear trail of prior art to compare against, and the BSD-3-Clause licensing of DeadMatter itself permits inspection and modification.

External validation exists in an unusual form for a small repo: DeadMatter was presented at Black Hat USA 2025 Arsenal, with the README linking to QSecure's announcement page. Arsenal acceptance is not a code audit, but it does mean the technique was subjected to public technical scrutiny, and the accompanying presentation presumably elaborates the offset-independent approach that the README only sketches. Professionals evaluating the tool for an authorized workflow would be well served by reading that material alongside the source.

From a purely defensive standpoint, DeadMatter deserves a place on the threat model map. Its carving approach means defensive detections keyed to minidump creation or specific offset-table signatures are less relevant than detections around memory acquisition itself, suspicious binary execution on endpoints, and post hoc credential rotation. Any host whose memory has been captured by an unauthorized party should have all extracted credential classes — NTLM hashes and DPAPI-protected secrets included — treated as compromised and rotated, because carving leaves no trace inside the image being parsed.

It is worth stressing the scope boundary the authors themselves draw. The disclaimer states the tool is intended solely for qualified information-security professionals during authorized penetration tests, red team engagements, or forensic investigations, and disclaims liability for misuse. That framing matches how the tool should be treated editorially: as offensive-security research tooling with a legitimate dual-use home in DFIR, not as something to point at systems you do not own. Running it against your own lab images or a client environment covered by a signed engagement letter is the intended context.

For practitioners already invested in the pypykatz ecosystem, the obvious question is what DeadMatter adds, and the honest answer today is: raw-image carving, on-host parsing without minidump generation, IV brute-forcing, and a C# codebase that integrates cleanly with Windows toolchains. What it subtracts is breadth — no Kerberos, WDigest, or live LSASS injection yet. Version 0.9.5_Beta is best understood as a focused carving engine with an ambitious roadmap, and at 69 stars it is early enough that engagement teams should validate its output against a known-good parser before trusting recovered hashes in reporting.

The installation story is minimal by design: it is a standalone C# executable, with the README showing direct invocation such as Deadmatter.exe -f memory_dump.raw against a local image. There is no package manager or server component to worry about, which keeps the operational surface small. Combined with its Black Hat Arsenal exposure and active roadmap, DeadMatter is a project worth monitoring for anyone whose authorized work involves memory analysis — on either the offensive or the investigative side of the fence.

Official project repository for qsecure-labs/DeadMatter.
Download Tool

Educational analysis for authorized security professionals. Use only in controlled, authorized environments.

Share articleFacebookXLinkedIn

Continue exploring

Browse all articles →

0 comentários:

Post a Comment

Note: Only a member of this blog may post a comment.