{"id":13799204,"url":"https://github.com/ropnop/windows_sshagent_extract","last_synced_at":"2026-03-06T07:03:08.497Z","repository":{"id":96506823,"uuid":"134171187","full_name":"ropnop/windows_sshagent_extract","owner":"ropnop","description":"PoC code to extract private keys from Windows 10's built in ssh-agent service","archived":false,"fork":false,"pushed_at":"2018-05-22T12:27:02.000Z","size":10,"stargazers_count":173,"open_issues_count":1,"forks_count":26,"subscribers_count":11,"default_branch":"master","last_synced_at":"2025-04-13T00:42:48.570Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/ropnop.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null}},"created_at":"2018-05-20T17:20:16.000Z","updated_at":"2025-02-15T06:48:52.000Z","dependencies_parsed_at":null,"dependency_job_id":"f0fdf157-9cac-4ae6-baa1-b1174dc2e19a","html_url":"https://github.com/ropnop/windows_sshagent_extract","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/ropnop/windows_sshagent_extract","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ropnop%2Fwindows_sshagent_extract","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ropnop%2Fwindows_sshagent_extract/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ropnop%2Fwindows_sshagent_extract/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ropnop%2Fwindows_sshagent_extract/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/ropnop","download_url":"https://codeload.github.com/ropnop/windows_sshagent_extract/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ropnop%2Fwindows_sshagent_extract/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":30164901,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-03-06T04:43:31.446Z","status":"ssl_error","status_checked_at":"2026-03-06T04:40:30.133Z","response_time":250,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.5:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-04T00:00:59.819Z","updated_at":"2026-03-06T07:03:08.466Z","avatar_url":"https://github.com/ropnop.png","language":"Python","funding_links":[],"categories":["[↑](#table-of-contents) [Credential Access](https://attack.mitre.org/tactics/TA0006/)","Python (1887)","Python"],"sub_categories":["[T1214 - Credentials in Registry](https://attack.mitre.org/techniques/T1214)"],"readme":"# Intro\nThese scripts are a PoC for how to extract unencrypted private SSH keys from Windows when the new OpenSSH `ssh-agent.exe` is used.\n\nWhen adding private keys to `ssh-agent`, Windows protects the private keys with DPAPI and stores them as registry entries under `HKCU:\\Software\\OpenSSH\\Agent\\Keys`\n\nWith elevated privileges, it is possible to pull out the binary blobs from the registry and unprotect them using DPAPI. These blobs can then be restructured into the original, unencrypted private RSA keys.\n\nAll credit for the Python code should go to the original implementatoin by soleblaze and his script `parse-mem.py` [here](https://github.com/NetSPI/sshkey-grab/blob/master/parse_mem.py)\n\n# Usage\nFrom an elevated Powershell prompt, use `extract_ssh_keys.ps1` to generate a JSON file which contains the Base64 data of the unprotected SSH keys. This script works by enumerating all SSH keys stored in the registry and calling DPAPI with the \"Current User\" context to unprotect the binary data.\n\n```\nC:\\tools\u003e .\\extract_ssh_keys.ps1\nPulling key:  .\\ropnopkey2\nPulling key:  .\\ropnopkey1\nextracted_keyblobs.json written. Use Python script to reconstruct private keys: python extractPrivateKeys.py extracted_keyblobs.json\n```\n\nThe Python script requires Python 3 and the `pyasn1` package. Run the Python script on the saved JSON file to re-construct the original, uncnecrypted RSA private keys:\n\n```\nC:\\tools\u003e python .\\extractPrivateKeys.py .\\extracted_keyblobs.json\n[+] Key Comment: .\\ropnopkey2\n-----BEGIN RSA PRIVATE KEY-----\nMIIEpAIBAAKCAQEAtekm5ikm0lh9fIiqslAUVUAhbI48/+khBFstx7jbz0XfcvAo\nXS3wxeer7UeaIXRJAXARy4ARi6fk9W6PfdP3zKFd7D1MV1WG0FAogxWUXOxiYxgZ\nyihsYNQ2NQmnVrW2C67+RZ2tTwNEEUGRVPi0QRjLlwXWPm6+0bFF4d0A7ivwTa0+\nEYVow48E74v5BMOxW+h87ZassRvAO22vZXV7Tr/VnwM3GoLPXTSAUxVsO0nhDs07\nJCXsu8oO7zH3Ql/I330QxAYo3qG0c/Ega3m474vVdIQOYdiaYxmN1u29wR9MAUNx\n/fY9yOTc0+prwWVt5GqZ3y89d9PI1VJfqNa6LQIDAQABAoIBAQCLjycHtxSQldEY\nBKWojWU8DipWZT2JO+rXs7gInNsORtXqETN2YTNyMY2mSaOG/PaxgrA0RrmvQgyW\n+s5dQ4y90iMDhfeWnQgDsyuRfbHIJJZK3geTH7YeB1DbGd/m1xumFQgAkrqOfrvu\n3TXJUdDAjGxNHe5DEaWVrIIniO0YyxMV10M2s2D6GtNHBjzop9YDegvkeQxNbO0K\ntKcDhJ/QPrkT+J8yCnRpStYC+kNlbOlBKkmdTJ5nhtmlZ8mWqpIgocvKrOZavsAh\n7SKpWt/Sjjoc+8wwt4dNiy8WnbHGFPb6W9lxdjDxpmoTn2bQOaS0oo61KJU7m60O\nSdgQwtUBAoGBAOXhnKWe2wKN/sx+/PYEvh2bi5xtugcOufCTqFlTYpxsgG0717s2\n1Ljwh7yjtTv6bS+6tXFrAy8QhKwLiuXnn8OAaPb9hMbpqGDhk04GcDWP/1oqS/2Y\ngMfeoBF6P3+q969kFbZwMCj/zsOEXnwTJGN6bxHBKassslts3Lf8jVjtAoGBAMqU\nQY0EebxJAQm3BgsQ0fsNli0CFGAm7iSlYmsSkcbcwZfL9hzxccKZDpZpXr2WV9wf\ndqfUoQyowSbZEz5kcuEeRe4Ofzf0ADs0fdMYRg0fvZ9JUCsTq+ecj3U25vNeXW9F\nkD7mYnEbY9lMkMvna4uthraxBQEZyyWjHsu2mP5BAoGBALukYFBUjeLU8zILSgKr\nNmBGkjw62Mlf/OjiLl3Tkb+rVV1UprCbfiIDvFh/rLTromp+VhLhTfUB37nrphIp\n8iAL1iIeKF6RZa7HEo1y9e7SvpXjxqmW7S+4iiIaDnDwpkLVSF/lzXn57NVtXA6d\nNWu6CaWNbazazC+Secv464u1AoGAdK2tj75bK3JU8baD+Y2nk9UAgU3oVHU3xs2n\nAQrCAesWagrk50i9gBrOBx4LnmDgm/1XR1U1qWftUCXJaq9KZ5UbLAEXjy+vjmou\nao5ZkqeMfRkp3pXG9nD7Q8TqgpQAdt13NnNVkdX3zanG4FqbW+kHZWRSAI9NrZDl\nZOn39sECgYBj6IPFbBxllysESiV6Tcvb98ffKjWBvL3MM4ENfzlH0fCNGNkVPDvn\nufMwjM3PqhUFXVBQHm0eMZDLLcLpLUxxIpiOdmLDk6XhAY+1Vc90OmDrCoADUxdg\nEq/hFJMNz4ZMio4KVd+BUVM2rt4zjq0tcxtOrMABdddCRBkuwhluSQ==\n-----END RSA PRIVATE KEY-----\n```\n\nBlog post here explaining my process: https://blog.ropnop.com/extracting-ssh-private-keys-from-windows-10-ssh-agent\n\n## Credits\nhttps://gist.github.com/atifaziz/10cb04301383972a634d0199e451b096\n\nhttps://blog.netspi.com/stealing-unencrypted-ssh-agent-keys-from-memory/\n\nhttps://github.com/NetSPI/sshkey-grab\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fropnop%2Fwindows_sshagent_extract","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fropnop%2Fwindows_sshagent_extract","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fropnop%2Fwindows_sshagent_extract/lists"}