DPAPI is a core Windows component designed to protect sensitive data by encrypting it using the user's logon credentials or the system's identity. It eliminates the need for applications to manage their own encryption keys.
DPAPI relies on a multi-layered key hierarchy to ensure that data remains inaccessible even if the physical disk is stolen.
Master Keys are 64-byte random values used to protect the "Session Keys" that actually encrypt the data. They are renewed every 90 days by default.
%APPDATA%\Microsoft\Protect\<UserSID>\C:\Windows\System32\Microsoft\Protect\S-1-5-18\HKLM\SECURITY\Policy\Secrets\$DPAPI_SYSTEMThe LSASS (lsass.exe) process manages DPAPI keys in memory. When a user logs in, LSA decrypts the Master Key and keeps it in memory so that the user doesn't have to provide their password every time an application requests data decryption.
Mock-up of LSA Memory (Readable Format):
LSA DPAPI Cache
- MasterKey GUID:
{A1B2C3D4-E5F6...}- Status: Decrypted / Active
- Plaintext Key:
0x89ABCDEF... (64 bytes)- Owner:
DOMAIN\User