■■■■□ 🖥️ VMkatz — Extract Windows Secrets from Virtual Machine Snapshots.
An open-source incident response and security research tool that analyzes virtual machine memory snapshots and disks to extract forensic artifacts and credential material from Windows systems during authorized assessments.
✨ Features
• 💾 Supports VMware, VirtualBox, QEMU/KVM, Hyper-V, and raw disk formats
• 🔍 Parses VM memory snapshots and offline Windows artifacts
• 🗝️ Extracts Kerberos tickets, DPAPI data, cached credentials, and other Windows secrets
• 📂 Supports offline analysis of SAM, LSA secrets, cached logons, and NTDS.dit
• 🔐 Includes BitLocker key extraction from supported memory snapshots
• ⚡ Runs as a compact static binary suitable for virtualization hosts
• 📊 Exports results in text, CSV, NTLM, and Hashcat-compatible formats
• 🛠️ Designed for DFIR, malware analysis, red team labs, and authorized security assessments
https://github.com/nikaiw/VMkatz
