Mimikatz is a widely used open-source Windows post-exploitation tool created by Benjamin Delpy for extracting and abusing authentication material from compromised systems. It is best known for dumping credentials from LSASS memory, recovering plaintext passwords in some configurations, extracting NTLM hashes and Kerberos secrets, and enabling credential abuse techniques such as pass-the-hash. Its functionality extends beyond local credential dumping to Active Directory abuse through modules such as DCSync and DCShadow, which leverage directory replication behavior to retrieve password hashes or modify directory attributes when the attacker already holds sufficiently privileged rights. Mimikatz is frequently used after initial compromise to escalate privileges, move laterally, and expand access across enterprise Windows environments.
The tool has been repeatedly observed in intrusion operations conducted by ransomware actors, botnet operators, and espionage groups, as well as embedded or adapted inside other malware and offensive tooling. Reported use includes deployment by operators associated with LockBit 2.0, Emotet follow-on activity, QakBot-related intrusions, Maze affiliate operations, and long-term server compromises involving custom webshells. Variants and derivatives such as Invoke-Mimikatz and SafetyKatz have been used to execute its credential-access capabilities through PowerShell, reflective loading, or minidump-based workflows intended to reduce detection. Mimikatz components or Mimikatz-like functionality have also been incorporated into malware families including Bad Rabbit, TrickBot modules, and banking malware that harvest credentials from Windows sessions.
Mimikatz primarily targets Windows systems and is associated with credential theft, privilege escalation, and post-exploitation activity. In domain environments, successful use can expose highly sensitive material such as domain account hashes and Kerberos-related secrets, enabling persistent administrative access and broad lateral movement when privileged accounts are compromised.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
48 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources.
BRONZE BUTLER ... Tools ... ABK, BBK, Casper, Daserf, Datper, DGet, down_new, Ghostdown, Gofarer, gsecdump, Mimikatz, MSGet, Netboy, RarStar, Screen Capture Tool, ShadowPad, ShadowPy, T-SMB
menuPass has used DLL side-loading to launch versions of Mimikatz and PwDump6 as well as UPPERCUT.
Mimikatz – an open source tool designed to extract and use credential information from Windows systems
Chafer has also continued to use tools previously associated with the group, including its own custom backdoor Remexi; the aforementioned PsExec; Mimikatz (Hacktool.Mimikatz), a free tool capable of changing privileges, exporting security certificates, and recovering Windows passwords in plaintext.
The system stealer attempts to obtain credentials from LSASS with a technique similar to that used by Mimikatz.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Either PowerShell or JavaScript is used to download the Trojan, which delivers a packed payload file to the victim machine.
This method uses .NET’s interop functionality to patch “amsi.dll”’s exported function “AmsiScanBuffer”... By modifying the function body by injecting our own assembly code, we can create a small stub which will always return a code indicating that a command is non-malicious.
Defense Evasion Process injection to hide beacon Credential Access mimikatz sekurlsa::logonpasswords T1003, T1055, T1093 hashdump T1003, T1055, T1093
Defense Evasion Process injection to hide beacon Credential Access mimikatz sekurlsa::logonpasswords T1003, T1055, T1093 hashdump T1003, T1055, T1093
The actor then issues a command that uses the “type” command to read the contents of the text file containing the passwords, followed by a command that uses “del” to delete the text file.
In case 1, after a successful exploitation, the attacker will authenticate using the DC computer account.
This method uses .NET’s interop functionality to patch “amsi.dll”’s exported function “AmsiScanBuffer”... By modifying the function body by injecting our own assembly code, we can create a small stub which will always return a code indicating that a command is non-malicious.
TrickBot uses mimikatz to harvest emails and other credentials. | screenLocker_x64.dll: a module for reconnaissance and credential harvesting. It uses a component of mimikatz to extract credentials from the target system.
T1003.001 – OS Credential Dumping: LSASS Memory The adversary dumped Local Security Authority Subsystem Service (LSASS) memory several times across multiple systems... using several open-source utilities, including nanodump and mimikatz. | the adversary leveraged the mimikatz tool, ‘m.exe’, to access additional valid credentials... The binary was used on multiple hosts to dump the memory of the LSASS process
DCSync、DCShadowの両方ともドメインコントローラーへのなりすましに起因する攻撃であり、端的に言うとDCSyncは情報取得が可能、DCShadowは情報の改ざんが可能である攻撃です。 まずは、DCSyncです。MS-DRSR...を用いて...Administrators、Domain Admins、Enterprise Admins、Domain Controllersグループに属しているアカウントの権限を用いて、ドメインコントローラーになりすまして利用者のパスワードハッシュ(NTLMハッシュ)を取得することができます。
Agent Tesla can gather credentials from a number of browsers... APT33 has used a variety of publicly available tools like LaZagne to gather credentials... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge... SELECT action_url, username_value, password_value FROM logins; CryptUnprotectData
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
リモートログイン … Pass-the-hash / Pass-the-ticket … Overpass-the-hash … Diamond Ticket … ドメイン管理者権限アカウントの奪取 … Mimikatz (Golden Ticket) Mimikatz (Silver Ticket)
Golden Ticket attack – Adversaries who have the KRBTGT account password hash may forge Kerberos ticket-granting tickets (TGT) called “Golden ticket” which enable adversaries to generate authentication material for any account in Active Directory. | The most well-known example of this is the Golden Ticket attack, which allows threat actors to forge a ticket to masquerade as a high-privileged user. | Both the Sapphire and Diamond Ticket attacks decrypt a legitimate TGT and change its PAC, and in order to do that, the adversary needs to have access to the KRBTGT account’s key (the password hash).
Pass-the-Hash with Mimikatz | Attackers can use Mimikatz to dump hashes, tickets, or plain text passwords.
リモートログイン RDP Pass-the-hash / Pass-the-ticket Mimikatz (Pass-the-Hash) WCE(リモートログイン) Overpass-the-hash
4. Overpass-the-hash (OPtH) The Overpass-the-hash technique applies the same concept as pass-the-hash with one key difference: it converts a hash into a fully fledged TGT ticket. | 2. Pass-The-Ticket Windows provides a native method to perform a very similar technique to the NETONLY flag using Kerberos ... arbitrarily change the cached Kerberos credentials (e.g., TGT) associated with their logon session.
124 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Post-compromise credential dumping tool used to extract LSASS credentials during Storm-1175 intrusions.
Credential-harvesting and post-exploitation tool used to dump credentials from compromised systems.
Credential theft and post-exploitation tool used to extract credentials from LSASS after initial access.
An offensive post-exploitation tool used by the attackers for credential theft during the intrusion.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.