Mimikatz is a widely used open-source Windows post-exploitation tool created by Benjamin Delpy for credential access and abuse of Windows authentication mechanisms. It is best known for extracting credentials from memory, including material from LSASS, and for enabling operators to obtain account secrets useful for privilege escalation, lateral movement, and broader domain compromise. Its functionality has made it a staple in both red-team operations and real-world intrusions by ransomware, espionage, and financially motivated actors.
Core capabilities include credential dumping from Windows logon sessions and abuse of Active Directory replication features through modules such as DCSync and DCShadow. DCSync can request directory replication data from domain controllers and retrieve password hashes, including highly sensitive domain secrets when the attacker has sufficient privileges. DCShadow can register a rogue domain controller context and push unauthorized directory changes through replication workflows, enabling stealthy manipulation of Active Directory attributes. Mimikatz is also commonly used in pass-the-hash and related post-compromise activity because the credentials it exposes can be reused to authenticate to additional systems without knowing plaintext passwords.
The tool is frequently deployed after initial access rather than serving as the initial infection payload itself. Threat actors have executed it directly, loaded modified variants reflectively or in memory, embedded Mimikatz-like components inside other malware, and downloaded it through PowerShell-based tradecraft. It has been observed in ransomware operations, enterprise intrusions, and webshell-enabled compromises, where it is used to dump credentials, escalate privileges, and accelerate lateral movement across Windows networks.
Mimikatz targets Windows environments, especially domain-joined enterprise systems where cached credentials, privileged logon sessions, and Active Directory trust relationships provide high-value opportunities. Because it is a dual-use tool rather than a self-propagating malware family, delivery varies by operator and campaign. Its enduring operational relevance stems from its broad credential-access feature set and its support for high-impact post-exploitation actions in Windows and Active Directory environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Recently, Microsoft issued the patch for CVE-2020-1472 a.k.a. Zerologon, a critical vulnerability that allows an attacker without credentials to elevate to the highest possible privileges in the domain.
The exploitation of ProxyShell in these attacks involves three vulnerabilities: CVE-2021-34473, CVE-2021-34523 and CVE-2021-31207 — the first two were patched in July 2021, while the latter was fixed in May 2021. | Mimikatz, a tool that allows users to view and save credentials and is often used for post-exploitation activities, was downloaded by PowerShell.
Mimikatz, a tool that allows users to view and save credentials and is often used for post-exploitation activities, was downloaded by PowerShell.
shortly afterwards, credential-dumping tool Mimikatz was used to dump credentials from the system.
shortly afterwards, credential-dumping tool Mimikatz was used to dump credentials from the system.
Mimikatz, a tool that allows users to view and save credentials and is often used for post-exploitation activities, was downloaded by PowerShell.
The fileless attack was delivered via Microsoft Word documents that exploited a former zero-day vulnerability in Word, CVE-2017-0199, to install a fileless attack variant of the Helminth Trojan agent. Microsoft released the patch for the vulnerability on April 11, but many organizations have not yet deployed the update.
Уязвимость RoguePlanet, ранее обнаруженная ИБ-исследователем Nightmare Eclipse, получила идентификатор CVE-2026-50656 (7,8 балла по шкале CVSS). Напомним, что проблема связана с возникновением состояния гонки в Microsoft Defender и позволяет повысить привилегии до уровня SYSTEM и выполнить произвольный код на полностью обновленных системах под управлением Windows 10 и Windows 11.
Security researchers, including Unit 42, have documented the use of coercion tools such as PetitPotam (CVE-2021-36942) in actual attacks. Microsoft has issued security advisories acknowledging the exploitation potential of this CVE.
Kaspersky researchers revealed ... the attackers exploit Internet-exposed Fortigate SSL VPN servers unpatched against the CVE-2018-13379 vulnerability ... The FBI and CISA warned ... APT actors scanning for Fortinet SSL VPN appliances vulnerable to CVE-2018-13379 exploits ... Fortinet also warned customers to patch their appliances against the CVE-2018-13379 ... "CVE-2018-13379 is an old vulnerability resolved in May 2019"
Earth Longzhi reimplemented some modules of Mimikatz ... as standalone binaries. ... We call this technique "Bring-Your-Own Mimikatz."
Rapid7’s Incident Response (IR) team was engaged to investigate an incident involving exploitation of CVE-2025-59718 against a vulnerable FortiGate appliance. In December 2025, Fortinet disclosed this improper verification of cryptographic signature vulnerability that facilitates an SSO login bypass on affected appliances.
Threat actors are suspected to be exploiting a maximum-severity security flaw impacting Quest KACE Systems Management Appliance (SMA) ... malicious activity ... consistent with the exploitation of CVE-2025-32975 on unpatched SMA systems exposed to the internet. CVE-2025-32975 (CVSS score: 10.0) refers to an authentication bypass vulnerability that allows attackers to impersonate legitimate users without valid credentials.
Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 | "...installed a variety of Mimikatz malware, which is used as a post-exploitation tool to steal passwords from memory..."
Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 | "...installed a variety of Mimikatz malware, which is used as a post-exploitation tool to steal passwords from memory..."
Attackers combine this with credential theft (Mimikatz/Pypykatz), lateral movement (Cobalt Strike, SystemBC), and backup destruction to maximize impact and enable double-extortion.
This analytic story covers attacks exploiting CVE-2024-4577, a remote code execution (RCE) vulnerability in the PHP-CGI implementation on Windows. Attackers leverage this vulnerability to gain initial access, deploy Cobalt Strike using the "TaoWu" kit for post-exploitation activities, and establish persistence.
Analysts confirmed that nation-state advanced persistent threat (APT) actors exploited CVE-2022-47966 to gain unauthorized access to a public-facing application (Zoho ManageEngine ServiceDesk Plus), establish persistence, and move laterally through the network. This vulnerability allows for remote code execution on the ManageEngine application.
"...a threat actor exploited the CVE-2022-40684 vulnerability to bypass authentication on the organization’s Fortinet VPN and gain initial access. Using various Windows tools and services, including smbexec.py from the Impacket toolkit, the attacker executed commands and moved laterally across the network."
48 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources.
BRONZE BUTLER ... Tools ... ABK, BBK, Casper, Daserf, Datper, DGet, down_new, Ghostdown, Gofarer, gsecdump, Mimikatz, MSGet, Netboy, RarStar, Screen Capture Tool, ShadowPad, ShadowPy, T-SMB
menuPass has used DLL side-loading to launch versions of Mimikatz and PwDump6 as well as UPPERCUT.
Mimikatz – an open source tool designed to extract and use credential information from Windows systems
Chafer has also continued to use tools previously associated with the group, including its own custom backdoor Remexi; the aforementioned PsExec; Mimikatz (Hacktool.Mimikatz), a free tool capable of changing privileges, exporting security certificates, and recovering Windows passwords in plaintext.
The system stealer attempts to obtain credentials from LSASS with a technique similar to that used by Mimikatz.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Either PowerShell or JavaScript is used to download the Trojan, which delivers a packed payload file to the victim machine.
This method uses .NET’s interop functionality to patch “amsi.dll”’s exported function “AmsiScanBuffer”... By modifying the function body by injecting our own assembly code, we can create a small stub which will always return a code indicating that a command is non-malicious.
Defense Evasion Process injection to hide beacon Credential Access mimikatz sekurlsa::logonpasswords T1003, T1055, T1093 hashdump T1003, T1055, T1093
Defense Evasion Process injection to hide beacon Credential Access mimikatz sekurlsa::logonpasswords T1003, T1055, T1093 hashdump T1003, T1055, T1093
In case 1, after a successful exploitation, the attacker will authenticate using the DC computer account.
This method uses .NET’s interop functionality to patch “amsi.dll”’s exported function “AmsiScanBuffer”... By modifying the function body by injecting our own assembly code, we can create a small stub which will always return a code indicating that a command is non-malicious.
The group actively re-purposes/uses Mimikatz and Advanced IP Scanner during their operation
Adversaries deploy vulnerable or stolen kernel drivers to terminate endpoint detection and response (EDR) software, dump cached credentials from LSASS memory
DCSync、DCShadowの両方ともドメインコントローラーへのなりすましに起因する攻撃であり、端的に言うとDCSyncは情報取得が可能、DCShadowは情報の改ざんが可能である攻撃です。 まずは、DCSyncです。MS-DRSR...を用いて...Administrators、Domain Admins、Enterprise Admins、Domain Controllersグループに属しているアカウントの権限を用いて、ドメインコントローラーになりすまして利用者のパスワードハッシュ(NTLMハッシュ)を取得することができます。
Agent Tesla can gather credentials from a number of browsers... APT33 has used a variety of publicly available tools like LaZagne to gather credentials... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge... SELECT action_url, username_value, password_value FROM logins; CryptUnprotectData
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
リモートログイン … Pass-the-hash / Pass-the-ticket … Overpass-the-hash … Diamond Ticket … ドメイン管理者権限アカウントの奪取 … Mimikatz (Golden Ticket) Mimikatz (Silver Ticket)
Golden Ticket attack – Adversaries who have the KRBTGT account password hash may forge Kerberos ticket-granting tickets (TGT) called “Golden ticket” which enable adversaries to generate authentication material for any account in Active Directory. | The most well-known example of this is the Golden Ticket attack, which allows threat actors to forge a ticket to masquerade as a high-privileged user. | Both the Sapphire and Diamond Ticket attacks decrypt a legitimate TGT and change its PAC, and in order to do that, the adversary needs to have access to the KRBTGT account’s key (the password hash).
Pass-the-Hash with Mimikatz | Attackers can use Mimikatz to dump hashes, tickets, or plain text passwords.
リモートログイン RDP Pass-the-hash / Pass-the-ticket Mimikatz (Pass-the-Hash) WCE(リモートログイン) Overpass-the-hash
4. Overpass-the-hash (OPtH) The Overpass-the-hash technique applies the same concept as pass-the-hash with one key difference: it converts a hash into a fully fledged TGT ticket. | 2. Pass-The-Ticket Windows provides a native method to perform a very similar technique to the NETONLY flag using Kerberos ... arbitrarily change the cached Kerberos credentials (e.g., TGT) associated with their logon session.
124 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used by the operators to dump credentials and harvest network secrets during post-compromise activity.
Post-exploitation tool used by the operator in its ransomware operations.
Post-exploitation credential theft and privilege-escalation tool explicitly described as used by the Majinahanashi operators during their operations.
Post-compromise credential dumping tool used to extract LSASS credentials during Storm-1175 intrusions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.