Mimikatz¶
Windows post-exploitation tool for extracting credentials, tickets, and secrets from memory and the local security databases.
When I Use It¶
- Recovering credentials from LSASS memory after gaining administrative access to a host
- Dumping local account hashes from the SAM, or domain secrets where available
- Kerberos ticket attacks (pass-the-ticket, and reference for golden/silver tickets)
Heavily detected; requires high privilege
Mimikatz is one of the most-signatured tools in existence; AV and EDR flag it on sight, and most functions need local administrator or SYSTEM. Expect detection on any monitored host, and confirm it is acceptable in scope. The point in a report is usually that it worked, which is itself the finding.
Installation¶
Obtain from the official repository: gentilkiwi/mimikatz. It is also loadable in memory through Meterpreter (load kiwi) and ported into other frameworks.
Common Modules¶
| Command | Purpose |
|---|---|
privilege::debug |
Acquire the debug privilege needed for most operations |
sekurlsa::logonpasswords |
Dump credentials of logged-on users from LSASS |
sekurlsa::tickets |
List and export Kerberos tickets in memory |
lsadump::sam |
Dump local account hashes from the SAM |
lsadump::lsa |
Dump LSA secrets |
lsadump::dcsync |
Request password data for an account from a DC (DCSync; needs replication rights) |
sekurlsa::pth |
Pass-the-hash: start a process as another user with their NTLM hash |
Reading the Output¶
sekurlsa::logonpasswordsreturns NTLM hashes and, on older or misconfigured systems, cleartext (WDigest)- Hashes feed Password Cracking or pass-the-hash for Movement
- A successful
dcsyncagainst a domain means the domain's credentials, includingkrbtgt, are exposed