Mimikatz
Executable
https://github.com/gentilkiwi/mimikatz/releases/download/2.2.0-20220919/mimikatz_trunk.zipgithub.com
Powershell
Invoke-Mimikatz
List active user sessions
Cache
SAM
SAM & LSA secretsLSA
SAM & LSA secretsLoad lsass.dump (extract from procdump or task manager)
LSASS secretsUser PrivilegesThen Pass The Hash
Pass the Hash (PtH)Export Tickets
Pass the Ticket (PtT) - WindowsIf you pick a ticket with the service krbtgt, it corresponds to the TGT of that account.
Extract Kerberos Keys
Pass the Ticket (PtT) - LinuxThen Pass the Key or OverPass the Hash
Pass the Key or OverPass the Hash
Pass the Ticket (PtT) - WindowsPass the Ticket (PtT)
Pass the Ticket (PtT) - WindowsWe can use the Mimikatz module misc to launch a new command prompt window with the imported ticket using the misc::cmd command
Kerberost
KerberoastIf we do not specify the base64 /out:true command, Mimikatz will extract the tickets and write them to .kirbi files
DCSync
DCSyncLast updated