BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//bsides-joburg-2026//talk//EFWTWY
BEGIN:VTIMEZONE
TZID:Africa/Johannesburg
BEGIN:STANDARD
DTSTART:20250725T000000
TZNAME:SAST
TZOFFSETFROM:+0200
TZOFFSETTO:+0200
END:STANDARD
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:Gimme! Gimme! Your Creds After Midnight: Weaponising Veeam Credent
 ial Extraction - Stephen\, Logan Kroeger
DTSTART;TZID=Africa/Johannesburg:20260725T102500
DTEND;TZID=Africa/Johannesburg:20260725T111000
DTSTAMP:20260726T032511Z
UID:pretalx-bsides-joburg-2026-EFWTWY@pretalx.com
DESCRIPTION:## Abstract\n\nBackup solutions deal with incredibly sensitive
  data\, and for ransomware to be truly effective\, backups are a primary t
 arget. One of the common backup technologies we encounter during red team 
 engagements is Veeam and it often stores highly privileged credentials nee
 ded to perform backup jobs across the environment. Domain Admin\, vSphere 
 administrator\, ESXi root: all sitting in a database\, encrypted with DPAP
 I\, waiting for someone to ask nicely.\n\nIn this talk\, we walk through h
 ow we went from manually extracting credentials from Veeam Backup & Replic
 ation and Veeam ONE databases to building and releasing VeeamDumper\, a .N
 ET tool and Beacon Object File (BOF) that automates the entire process. We
 'll cover the credential storage mechanisms and encryption differences bet
 ween VBR and Veeam ONE (including the undocumented Veeam ONE entropy value
  we had to figure out ourselves)\, the DPAPI decryption chain\, and how ex
 tracted credentials map to infrastructure targets for lateral movement.\n\
 nBeyond the tool itself\, we'll break down the process of porting a .NET p
 ost-exploitation tool into a BOF including the design decisions\, the pain
  points\, and why having both gives operators flexibility across different
  C2 frameworks. We'll demonstrate VeeamDumper live\, from enumeration thro
 ugh to cleartext credential extraction and target mapping.\n\nWe'll close 
 with the defender's perspective: what makes Veeam infrastructure vulnerabl
 e\, why domain-joining backup servers to your primary AD domain is asking 
 for trouble\, and practical hardening steps to stop us from doing exactly 
 what we just showed you.\n\nVeeamDumper will be released as open-source pr
 ior to this talk.
LOCATION:Track 2
URL:https://pretalx.com/bsides-joburg-2026/talk/EFWTWY/
END:VEVENT
END:VCALENDAR
