Metcalf, S. (2015, November 13). Unofficial Guide to Mimikatz & Command Reference. Retrieved December 23, 2015.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1098 Account Manipulation |
ToolMimikatz | The Mimikatz credential dumper has been extended to include Skeleton Key domain controller authentication bypass functionality. The |
| T1134.005 SID-History Injection |
ToolMimikatz | Mimikatz's |
| T1207 Rogue Domain Controller |
ToolMimikatz | Mimikatz’s |
| T1550.002 Pass the Hash |
ToolMimikatz | Mimikatz's |
| T1550.003 Pass the Ticket |
ToolMimikatz | Mimikatz’s |
| T1552.004 Private Keys |
ToolMimikatz | Mimikatz's |
| T1649 Steal or Forge Authentication Certificates |
ToolMimikatz | Mimikatz's `CRYPTO` module can create and export various types of authentication certificates. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.