Invoke-Mimikatz is a PowerShell implementation and in-memory execution wrapper for Mimikatz functionality on Windows systems. It is commonly used after initial compromise to execute credential-access operations through PowerShell, often with obfuscation or encoded commands to reduce visibility and complicate forensic analysis. The tool is closely associated with post-exploitation activity in enterprise Windows environments and is frequently discussed in the context of credential theft, privilege escalation support, and defense evasion.
Invoke-Mimikatz has been observed in intrusion activity attributed to Kimsuky, which executed it through PowerShell as part of broader Windows-focused operations. It is also widely referenced in defensive guidance because its execution produces distinctive PowerShell telemetry under module logging and script block logging, including de-obfuscated script content when appropriate logging is enabled. Adversaries commonly attempt to run it in memory and disguise or obfuscate its execution to evade detection.
The tool has also been used in demonstrations of Windows security-control bypass techniques, including scenarios where malicious execution is made to appear as a trusted Windows process. In such contexts, Invoke-Mimikatz serves as a representative post-compromise payload for testing or abusing weaknesses in endpoint visibility. Its operational role is best characterized as a credential-focused post-exploitation utility executed via PowerShell on Windows.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Kimsuky has executed a variety of PowerShell scripts including Invoke-Mimikatz.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
The workflow uses PowerShell to download, load, and execute AMSI-bypass, Mimikatz, PowerUp, and NTDS/SAM-dumping scripts, including commands piped into Invoke-Expression.
This method uses .NET’s interop functionality to patch “amsi.dll”’s exported function “AmsiScanBuffer”... By modifying the function body by injecting our own assembly code, we can create a small stub which will always return a code indicating that a command is non-malicious.
attackers can manipulate these links so that trusted Windows paths point to malicious files instead of legitimate ones, enabling malware to execute while appearing harmless to security applications.
This method uses .NET’s interop functionality to patch “amsi.dll”’s exported function “AmsiScanBuffer”... By modifying the function body by injecting our own assembly code, we can create a small stub which will always return a code indicating that a command is non-malicious.
"let’s use Mimikatz to grab credentials" and "With enough privileges, we can dump NTDS and SAM."
"Instead, let’s dump LSASS locally and see what’s there in the results: ... Invoke-Mimikatz -DumpCreds."
This module executes PowerSploit's Invoke-Mimikatz.ps1 script (Mimikatz's DPAPI Module) and extract cached credentials from memory from the LSASS subsystem.
Stracciatella D:\> . .\Invoke-Mimikatz.ps1 ... Stracciatella D:\> Invoke-Mimikatz -Command "coffee exit"
CRYPTO::Certificates – list/export certificates... Typical use is to export certificates that aren’t marked as “exportable.”... Use mimikatz to export all private certificates (even if they are marked non-exportable): Invoke-Mimikatz – DumpCerts
if Invoke-Mimikatz is run with the appropriate rights and the target computer has PowerShell Remoting enabled, it can pull credentials from other systems, as well as execute the standard Mimikatz commands remotely, without files being dropped on the remote system.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A post-exploitation credential theft tool/script used here as the demonstration payload for bind-link-based EDR evasion by masquerading as a trusted Windows process.
A PowerShell-based in-memory execution method for Mimikatz, used to avoid disk artifacts and complicate forensic analysis.
A PowerShell implementation associated with credential theft activity, observed here being downloaded and executed through malicious PowerShell commands.
PowerShell implementation/wrapper used to load and run Mimikatz functionality in-memory for credential theft (e.g., LSASS credential dumping).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.