Mimikatz

S0002

Tool.View on attack.mitre.org

About this tool

Mimikatz is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along with many other features that make it useful for testing the security of networks.

Techniques used17

Procedure examples17

TechniqueProcedure example
T1003.001
LSASS Memory

Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the LSASS Memory.

T1003.002
Security Account Manager

Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the SAM table.

T1003.004
LSA Secrets

Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the LSA.

T1003.006
DCSync

Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from DCSync/NetSync.

T1098
Account Manipulation

The Mimikatz credential dumper has been extended to include Skeleton Key domain controller authentication bypass functionality. The LSADUMP::ChangeNTLM and LSADUMP::SetNTLM modules can also manipulate the password hash of an account without knowing the clear text value.

T1134.005
SID-History Injection

Mimikatz's MISC::AddSid module can append any SID or user/group account to a user's SID-History. Mimikatz also utilizes SID-History Injection to expand the scope of other components such as generated Kerberos Golden Tickets and DCSync beyond a single domain.

T1207
Rogue Domain Controller

Mimikatz’s LSADUMP::DCShadow module can be used to make AD updates by temporarily setting a computer to be a DC.

T1547.005
Security Support Provider

The Mimikatz credential dumper contains an implementation of an SSP.

T1550.002
Pass the Hash

Mimikatz's SEKURLSA::Pth module can impersonate a user, with only a password hash, to execute arbitrary commands.

T1550.003
Pass the Ticket

Mimikatz’s LSADUMP::DCSync and KERBEROS::PTT modules implement the three steps required to extract the krbtgt account hash and create/use Kerberos tickets.

T1552.004
Private Keys

Mimikatz's CRYPTO::Extract module can extract keys by interacting with Windows cryptographic application programming interface (API) functions.

T1555
Credentials from Password Stores

Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the credential vault and DPAPI.

T1555.003
Credentials from Web Browsers

Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from DPAPI.

T1555.004
Windows Credential Manager

Mimikatz contains functionality to acquire credentials from the Windows Credential Manager.

T1558.001
Golden Ticket

Mimikatz's kerberos module can create golden tickets.

View all 17 procedure examples

Groups that use it51

Show 27 more

Campaigns9

References2

  1. Adsecurity Mimikatz Guide Open source
    Metcalf, S. (2015, November 13). Unofficial Guide to Mimikatz & Command Reference. Retrieved December 23, 2015.
  2. Deply Mimikatz Open source
    Deply, B. (n.d.). Mimikatz. Retrieved September 29, 2015.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.