Mimikatz is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along with many other features that make it useful for testing the security of networks.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the LSASS Memory. |
| T1003.002 Security Account Manager |
Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the SAM table. |
| T1003.004 LSA Secrets |
Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the LSA. |
| T1003.006 DCSync |
Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from DCSync/NetSync. |
| T1098 Account Manipulation |
The Mimikatz credential dumper has been extended to include Skeleton Key domain controller authentication bypass functionality. The |
| T1134.005 SID-History Injection |
Mimikatz's |
| T1207 Rogue Domain Controller |
Mimikatz’s |
| T1547.005 Security Support Provider |
The Mimikatz credential dumper contains an implementation of an SSP. |
| T1550.002 Pass the Hash |
Mimikatz's |
| T1550.003 Pass the Ticket |
Mimikatz’s |
| T1552.004 Private Keys |
Mimikatz's |
| T1555 Credentials from Password Stores |
Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the credential vault and DPAPI. |
| T1555.003 Credentials from Web Browsers |
Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from DPAPI. |
| T1555.004 Windows Credential Manager |
Mimikatz contains functionality to acquire credentials from the Windows Credential Manager. |
| T1558.001 Golden Ticket |
Mimikatz's kerberos module can create golden tickets. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.