SoftDroids.net » Windows » Safety » Mimikatz


Mimikatz

5
Mimikatz
Download
Category: Safety
System: Windows XP, Windows Vista, Windows 7, Windows 8, Windows 8.1, Windows 10
Program Status: Free
Looking at the file: 409

Description

Mimikatz is a Windows application that allows you to retrieve valid passwords from a hibernation file or RAM dump. A list of active users is displayed, and it is possible to retrieve keys in plain text. Administrator rights are required to access all functions.

Principle of operation

To protect passwords, Windows stores them in encrypted form. The complexity of the algorithm practically eliminates the possibility of picking up the password with the help of a classic bruteforce. However, some services use the key in clear form during their work. This feature is used by the application to access the password. The vulnerability makes it possible to extract the required area without complex manipulations and immediately get the information in clear form. At the same time, there is no need to use complex calculations.

Password interception

After downloading the application to your PC, open the directory and select the executable file according to the system bitness. It is necessary to run it as an administrator. Then in a special window enter the command "privilege::debug", then "sekurlsa::logonPasswords full". As an answer, a list of active users will be displayed, next to each will be the corresponding password. To capture the key that is in the memory dump you should use PowerShell application. After launching the terminal, you must enter the construct "Get-Process lsass | Out-Minidump". This will initiate the saving of an image with the DMP extension in the system directory. This file should be transferred to another PC and use the command "sekurlsa::minidump", the correct dump name should be specified as an argument. At the last step you need to enter the command "sekurlsa::logonPasswords", which will display a set of logins and passwords.

Features

  • the application allows you to retrieve passwords of active users;
  • memory dump is used to retrieve keys;
  • peculiarities of some Windows components are used;
  • DMP image file is used as an intermediate result;
  • administrator rights are required to work;
  • the program can be downloaded for free.
Screenshots

See also:

Depositphotos Depositphotos
Depositphotos is an official Android application for interacting with the Internet service of the...
Crunchyroll Crunchyroll
Crunchyroll is an anime app for Android devices. The built-in catalog contains several thousand...
AppForType AppForType
AppForType is a special program that allows you to edit photos very easily. It is worth noting that...
xrsound dll xrsound dll
The xrsound.dll file is a typical library for the Windows platform. It is part of the game Stalker...
Viper FX Viper FX
Viper FX is a utility that is actually a system equalizer. This software is designed for Android...
SmartClick SmartClick
SmartClick is a useful mobile client for Android devices. Its main task is to click buttons in...
FVD Speed Dial FVD Speed Dial
FVD Speed Dial is a useful extension for the browser that allows you to change the standard panel...
Adobe Character Animator Adobe Character Animator
Adobe Character Animator is a special program that comes in handy for everyone who works with 2D...
Comments (0)
Commenting
Comment