module

Veeam Backup and Replication Credentials Dump

Disclosed
2022-11-22
Created
2023-02-02

Description

This module exports and decrypts credentials from Veeam Backup & Replication and
Veeam ONE Monitor Server to a CSV file; it is intended as a post-exploitation
module for Windows hosts with either of these products installed. The module
supports automatic detection of VBR / Veeam ONE and is capable of decrypting
credentials for all versions including the latest build of 11.x.

Author

npm npm@cesium137.io

Platform

Windows

Module Options

To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:


msf > use post/windows/gather/credentials/veeam_credential_dump
msf post(veeam_credential_dump) > show actions
...actions...
msf post(veeam_credential_dump) > set ACTION < action-name >
msf post(veeam_credential_dump) > show options
...show and set options...
msf post(veeam_credential_dump) > run

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.