Extracting AES key from running process using AES Finder

AES finder is cool tool to find AES keys in process memory. It looks for Cipher initialization (and equivalent). It does not perform lookup using entropy calculation. If key was generated but not used it will not be revealed. Great tool :)

Encryption Key

AES key is visible at bottom. Key derived from passphase

Encryption and Decryption Key

Key created but cipher not initialized