Mimikatz
Last updated
Last updated
A little tool to play with Windows security
Launch mimikatz (as Administrator!)
Engage SeDebugPrivilege
-> OK
Whoami
Dump creds of all logged-on users
(Optional) Impersonate to nt authority\system
Dump sam database
Show tickets
Export tickets
Locally?
From DC?
-> Look for "[domainkey]", decrypt using same command with /rpc