Skip to content

0xRedpoll/SignalKeyBOF

Repository files navigation

SignalKeyBOF

A Cobalt Strike BOF and Python helper script to retrieve the decryption keys for the compromised hosts Signal Desktop database.

Warning

Only works on Windows hosts with Signal Desktop installed and used.

Requirements

  • A Cobalt Strike beacon on a compromised host
  • Python packages (which I haven't kept track of, requirements.txt to come)

Build Info

make all

Usage

SignalKeyBOF

Example execution

Acknowledgements

  • TrustedSec's CS-Remote-OPs-BOFs for their Slack Key BOF which this is heavily inspired by.
  • Carderne's Signal-Export tool which the helper script is heavily inspired by.

License

GPLv3

Author Information

This tool was created by 0xRedpoll.

About

BOF to decrypt Signal Desktop chat logs

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors