Kali Linux

Tofu : Windows Offline Filesystem Hacking Tool For Linux

Tofu is a modular tool for hacking offline Windows filesystems and bypassing login screens. Can do hashdumps, OSK-Backdoors, user enumeration and more.

How It Works

When a Windows machine is shut down, unless it has Bitlocker or another encryption service enabled, it’s storage device contains everything stored on the device as if it was unlocked. This means that you can boot from an operating system on a bootable USB and access it’s files – or even just connect the filesystem to another computer.
This tool helps for when you can access the Windows filesystem from Linux (using one of the mentioned methods); it has utilities that can dump NTLM password hashes, list users, install backdoors to spawn an elevated command prompt at the login screen and more.

Modules

Because tofu works on modules, it can be expanded for different purposes. See the ‘modules’ section for examples.
Current Modules:
1. hashdump.py – Dumps NTLM hashes from the target Windows filesystem
2. osk_backdoor.py – Backdoor osk.exe to bypass the login; also includes an ‘unbackdoor’ module
3. list_users.py – List the users with a profile on the Windows filesystem
4. chrome.py – Dump chrome history and login data of all users on the Windows filesystem
5. get_dpapi_masterkeys.py – Dump DPAPI master keys from the Windows filesystem
6. enum_unattend.py – Enumerate unattend files
7. memory_strings.py – Search through the memory of the computer to find data
8. startup.py – Inject a program into a user’s startup directory
9. wifi.py – Get Wi-Fi passwords with DPAPI

Usage

‘list’ : List all storage devices at /dev/ with a format of MSDOS, NTFS or -FVE-FS- (BITLOCKER) ; This will load the drive paths into memory
‘usedrive’ : Set the drive to use; can use numbers assigned from the ‘list’ command
‘modules’ : List modules ; This will load the module names into memory, so you need to run this command before selecting a module
‘use’ : Use the selected module

Setup

(need to run as root because PyPyKatz’ import path directory is dependent on the current user, and this needs to run as root)
sudo pip3 install -r requirements.txt
sudo python3 tofu.py

Built With

PyCryptodome
PypyKatz

Warning : If you’re writing a module, make sure it won’t do any damage before running it

R K

Recent Posts

Install Docker on Ubuntu 26.04: Official Repository Setup Guide

Install Docker on Ubuntu 26.04: Official Repository Setup GuideDocker is an open-source container platform that…

1 day ago

Install Asterisk on Ubuntu 18.04: Source Build and Secure Config

Asterisk is the most widely deployed open-source PBX (Private Branch Exchange) platform in the world. It…

2 days ago

Install Ghost on Ubuntu 18.04: Node.js, MySQL, and Nginx SSL

Ghost is an open-source publishing platform built on Node.js. It is designed for bloggers, journalists, and…

2 days ago

Install Mattermost on Ubuntu 18.04: Nginx SSL Reverse Proxy Setup

Mattermost is an open-source, self-hosted team messaging platform and a direct alternative to Slack. It is…

2 days ago

Install Ruby on Ubuntu 18.04: apt, Rbenv, and RVM Methods

Ruby is a dynamic, open-source programming language known for its clean, readable syntax. It powers the…

2 days ago

Install PyCharm on Ubuntu 18.04: Community Edition via Snap

PyCharm is a full-featured Python IDE developed by JetBrains. It includes built-in debugging, embedded Git control,…

2 days ago