Mimikatz
A little tool to play with Windows security GitHub - gentilkiwi/mimikatz
Passwords & SAM
Launch mimikatz (as Administrator!)
Engage SeDebugPrivilege
-> OK
Whoami
Dump creds of all logged-on users
(Optional) Impersonate to nt authority\system
Dump sam database
Tickets
Show tickets
Export tickets
Credential manager saved credentials
howto ~ credential manager saved credentials · gentilkiwi/mimikatz Wiki · GitHub
Locally?
From DC?
-> Look for "[domainkey]", decrypt using same command with /rpc
Last updated