What Is Mimikatz? How It Works, Detection & Defense

Mimikatz is an open-source tool that extracts Windows credentials from memory. Learn how it works, its modules, the attacks it enables, and how to detect it.
Published on
Monday, September 21, 2026
Updated on
September 20, 2026

Mimikatz is an open-source Windows tool that extracts authentication material from a system's memory, including plaintext passwords, NTLM hashes, PINs, and authentication tickets such as Kerberos tickets.

Attackers run the tool after they already hold administrator access on a host, then reuse the recovered credentials to authenticate elsewhere on the network.

Windows keeps credential material in memory, so users authenticate once and then access file shares, email, and applications without retyping passwords. 

The tool exploits no vulnerability. It reads the same memory that single sign-on relies on, so patching alone never removed the risk.

Mimikatz Origins: A Proof of Concept That Outlived Its Purpose

Benjamin Delpy, a French security researcher known as gentilkiwi, wrote Mimikatz in C in 2007 to study how Windows handles credentials.

That first version targeted pass-the-hash techniques that were already well documented, and the project grew as Delpy mapped more of the authentication stack.

Delpy released the tool publicly as version 1.0 in 2011 and reported the underlying credential-storage weakness to Microsoft. Microsoft's position at the time was that the technique required an already compromised machine, so the behavior remained in place, and the tool continued to work across successive Windows releases.

Nearly two decades later, the project remains open source and actively developed. Anyone can compile it from source, rename it, or load it directly in memory, so blocking a single file hash accomplishes very little.

How Mimikatz Extracts Credentials From Windows Memory

Mimikatz extracts credentials by reading the memory of the Windows process that stores authentication material for logged-on sessions, then decoding the structures it finds there.

mimikatz working infographic

LSASS and Windows Single Sign-On

The Local Security Authority Subsystem Service (LSASS) enforces local security policy, validates logons, and holds the secrets that make single sign-on possible. Each interactive logon, service account start, and scheduled task run leaves credential material in that process.

Every credential in LSASS belongs to a session that the operating system trusts. Mimikatz reads those structures directly and returns the secrets in a usable form.

Privileges Mimikatz Requires

Mimikatz requires local administrator or SYSTEM rights, since opening a handle to LSASS requires debug privilege.

Execution lands in the middle of an intrusion: after initial access through phishing, stolen credentials, or an exploited service, and before lateral movement across the domain.

Credential Types Mimikatz Recovers

  • NTLM password hashes: Cryptographic representations of passwords that authenticate directly through pass-the-hash.
  • Kerberos tickets and encryption keys: Ticket-granting tickets, service tickets, and the keys used to request new ones.
  • Plaintext passwords: Recoverable where WDigest or similar legacy providers are enabled on a host.
  • SAM database hashes: Local account hashes stored in the registry of the machine.
  • LSA secrets: Service account passwords, scheduled task credentials, and cached machine secrets.
  • Cached domain credentials: Verifiers stored so domain users log on when a domain controller is unreachable.
  • DPAPI master keys: Keys that decrypt browser passwords and Windows Credential Manager entries.
  • Certificates and private keys: Exportable material from the Windows certificate store, including keys marked non-exportable.

Offline Dumping Without Running Mimikatz

Attackers split the operation into two whenever they want to avoid running the tool on the victim host. A signed Windows binary such as Task Manager, ProcDump, or rundll32 with comsvcs.dll writes an LSASS memory dump to disk.

Mimikatz then parses that dump later, on attacker infrastructure, far from the victim network.

Microsoft's security researchers documented this pattern because it defeats controls tuned to Mimikatz itself. The activity on the victim host looks like an administrator capturing a crash dump, while the credential extraction happens somewhere with no monitoring at all.

Mimikatz Modules and What Each One Targets

Mimikatz splits its capabilities into modules, and each module maps to a distinct defensive concern:

  • sekurlsa: Reads credential material from LSASS memory, including logon passwords, Kerberos tickets, and encryption keys.
  • lsadump: Extracts secrets from the SAM database, LSA secrets, cached credentials, and domain controller replication.
  • kerberos: Requests, exports, imports, and forges Kerberos tickets.
  • crypto: Interacts with the CryptoAPI and certificate store, including export of private keys.
  • vault: Lists Windows Credential Manager vaults and the credentials stored inside them.
  • token: Lists and impersonates Windows access tokens belonging to other logged-on users.
  • privilege: Enables the debug privilege that the memory-reading modules depend on.
  • process and misc: Utility functions for process control, service manipulation, and assorted helpers.

Module names carry detection value, a point covered in the detection section below. Red Canary reports that sekurlsa::logonpasswords stays the most observed module year after year, followed by ticket listing and SAM dumping.

Attacks Built on Mimikatz Output

Credential material recovered by Mimikatz feeds four attack techniques that authenticate without ever knowing a password, all catalogued in the MITRE ATT&CK framework.

Pass-the-Hash

An NTLM hash authenticates to any system that accepts NTLM, because the protocol treats the hash as the secret (T1550.002). Local administrator accounts sharing one password across many machines turn a single dumped hash into access across an entire estate.

Pass-the-Ticket and Overpass-the-Hash

Attackers inject stolen Kerberos tickets into a new logon session, then replay them against services until the tickets expire (T1550.003).

Overpass-the-hash converts a recovered NTLM hash or AES key into a valid ticket-granting ticket, upgrading a hash into full Kerberos access.

DCSync

An account with directory replication rights asks a domain controller to send password data for any account, mimicking normal replication traffic between controllers (T1003.006).

One such request produces the KRBTGT hash and every user hash in the domain, without touching a single file on the controller.

Golden and Silver Tickets

A KRBTGT hash allows an attacker to forge ticket-granting tickets for any user, including accounts that never existed, which is the golden ticket attack (T1558.001).

Stolen service account hashes allow forged service tickets for a single service, known as silver tickets (T1558.002).

Forged tickets survive password resets on the compromised user accounts, so recovery requires rotating the KRBTGT account twice. Mapping the resulting access across systems is where an attack path view helps responders see how far one dumped hash reaches.

Mimikatz in Ransomware and Espionage Campaigns

Joint government advisories place Mimikatz inside ransomware operations that agencies actively investigate. The FBI, CISA, and Australian Signals Directorate advisory on Play ransomware documents the group using Mimikatz to obtain domain administrator credentials.

Its June 2025 update recorded approximately 900 affected entities as of May 2025, three years after the group first appeared.

A multi-agency update to the Akira ransomware advisory in November 2025 described the same credential-dumping stage, including extraction from LSASS dump files. Closed operations such as SafePay follow the same sequence with different tooling, which makes credential theft a shared checkpoint across ransomware campaigns.

NotPetya remains the most destructive example of Mimikatz-derived code inside a self-spreading payload. The 2017 wiper carried a credential stealer built on that code alongside exploit-based spreading.

Harvested passwords let the malware reach machines that were fully patched, because valid credentials need no vulnerability.

State-sponsored groups adopted the tool for the same reason criminal operators did. Public reporting ties Mimikatz to dozens of tracked intrusion sets, where it appears mid-campaign during the credential access stage of an advanced persistent threat operation.

Does Mimikatz Still Work on Windows 11 and Windows Server 2025?

Yes, Mimikatz still works, though modern Windows defaults block its most direct techniques on hardware that supports them.

  • Credential Guard: Microsoft enables Credential Guard by default starting with Windows 11 version 22H2 and Windows Server 2025 on domain-joined systems that meet the hardware requirements. Secrets move into a virtualization-based container that standard LSASS reads cannot open.
  • LSA protection: Running LSASS as a protected process blocks unsigned code from opening a handle to it. Microsoft now enables LSA protection by default, immediately on new installations and after a five-day evaluation period on upgrades.
  • WDigest: Plaintext password caching has been off by default since Windows 8.1 and Windows Server 2012 R2, which removes the clear-text output that made early Mimikatz demonstrations memorable.

Coverage gaps remain wide across real estate, for reasons that have nothing to do with the features themselves. Older servers, workgroup machines, and virtual desktops without the required hardware all leave LSASS readable.

Devices upgraded from earlier builds with the features explicitly disabled remain in the same position. Attackers holding SYSTEM rights load signed vulnerable drivers to strip process protection where it is enabled.

Kerberos abuse survives all three controls because forged tickets need no access to LSASS memory. Credential Guard protects secrets on the host, and a golden ticket forged from a stolen KRBTGT hash still authenticates normally.

Detecting Mimikatz Activity in Enterprise Environments

To detect Mimikatz, security teams monitor process access to LSASS, command-line arguments containing module names, and the artifacts the tool leaves behind, because file signatures alone miss recompiled and in-memory variants.

Command-Line and Module Indicators

Module strings such as sekurlsa::logonpasswords, sekurlsa::tickets, sekurlsa::ekeys, and lsadump::sam appear in process command lines and PowerShell script block logs.

PowerShell wrappers add their own signals. Red Canary identifies Invoke-Mimikatz with a credential-dumping parameter as the most common execution method in its telemetry.

LSASS Handle and Process Access Signals

Sysmon Event ID 10 records which process opened a handle to lsass.exe and with what access rights. The access-rights combinations used for memory reading stand out against normal activity.

Windows Security auditing produces equivalent visibility through object access events, once a system access control list is configured on the LSASS process.

Signed Microsoft binaries deserve the same scrutiny as unknown executables here. Dump creation through ProcDump, Task Manager, or rundll32 calling comsvcs.dll MiniDump generates LSASS access from tools that administrators rarely aim at that process.

File and Authentication Artifacts

Kerberos ticket files carry the .kirbi extension, and Red Canary recommends alerting on their creation because exported tickets precede replay attacks. Large dump files written to temporary directories point to the offline extraction path.

Authentication telemetry closes the loop once stolen credentials leave the host. A workstation that suddenly authenticates as several privileged accounts, or a service account logging on interactively for the first time, indicates that dumped credentials are already in use and belongs in security monitoring rules.

Why Many Mimikatz Detections Turn Out to Be Authorized Testing

Red team exercises and control validation generate a large share of real-world Mimikatz alerts. Red Canary's analysis found that removing customer-confirmed testing dropped Mimikatz from affecting 7.2% of monitored customers to 3.1%.

Its analysts assessed that even the remaining ranking stayed inflated by testing nobody reported.

Alert triage for this tool starts with attribution, not severity. A SOC that maintains a current register of authorized testing, scoped hosts, and test windows resolves these alerts in minutes.

Teams without that register treat every simulation as an active intrusion, and lose the hours they need for the real ones.

Defending Against Mimikatz Credential Theft

Defense against Mimikatz works by removing credentials from memory, restricting where privileged accounts log on, and detecting the reuse that follows a successful dump.

  1. Enable Credential Guard and LSA protection across the estate, and audit for devices where hardware limits or legacy policy leave them off.
  2. Confirm WDigest stays disabled and alert on registry changes that re-enable plaintext credential caching.
  3. Adopt a tiered administration model so domain administrator credentials never authenticate on workstations or general-purpose servers.
  4. Randomize local administrator passwords with Windows LAPS, which breaks pass-the-hash reuse across machines.
  5. Restrict directory replication rights to domain controllers and audit accounts holding them, since DCSync abuses that permission.
  6. Rotate the KRBTGT password twice on a schedule and immediately after any suspected domain compromise.
  7. Block unsigned and vulnerable drivers with the Microsoft-recommended driver block list, closing the route used to strip LSASS protection.
  8. Enable EDR tamper protection and alert when security agents stop reporting from a host.
  9. Segment administrative access behind zero trust controls and jump hosts so a dumped credential reaches a limited set of systems.
  10. Monitor for credentials exposed outside the network, including infostealer logs and dark web marketplaces that supply the initial foothold.

Legal and Authorized Use of Mimikatz

Legality turns entirely on authorization. Possession and study of Mimikatz stay lawful in most jurisdictions, and running it against systems without permission constitutes unauthorized access under computer misuse law.

  • Authorized testing: Penetration tests and red team exercises covered by a signed scope and rules of engagement.
  • Security research: Isolated lab environments used to study Windows internals and build detections.
  • Incident response: Controlled use by responders to confirm what credentials an intrusion exposed.
  • Unauthorized access: Execution on systems outside an approved scope, which carries criminal liability regardless of intent.

Internal policy sets the practical boundary for most enterprise security teams. Many organizations require named approval, defined hosts, logging, and time windows before any credential-dumping tool runs, and classify malware-adjacent tooling under the same change controls.

Mimikatz FAQs

What does the name Mimikatz mean?

Mimikatz comes from French slang for cute cats, chosen by its author Benjamin Delpy, whose online handle gentilkiwi follows the same playful naming style.

Does Mimikatz work on Linux or macOS?

No. Mimikatz targets Windows authentication components, though tools such as Impacket run comparable credential attacks against Windows systems from Linux hosts.

Can Windows Defender detect Mimikatz?

Yes, for the standard binary. Recompiled, renamed, or reflectively loaded variants evade signature detection and require behavioral rules on LSASS access.

Does Mimikatz bypass multi-factor authentication?

In effect, yes. Reused hashes and Kerberos tickets authenticate at the protocol level, skipping the interactive sign-in flow where MFA is enforced.

What is the difference between Mimikatz and Impacket secretsdump?

Mimikatz extracts credentials from memory on a compromised host. Impacket secretsdump pulls SAM, LSA, and NTDS secrets remotely over the network.

Is Mimikatz classified as malware?

Security vendors flag it as a hacktool or riskware. Its author built it for research, and threat actors use the same builds during intrusions.

Credential Exposure Before Mimikatz: Where CloudSEK Fits

CloudSEK does not detect Mimikatz execution on an endpoint. That job belongs to EDR and identity threat detection tooling watching LSASS access and authentication behavior inside the network.

Everything that precedes the dump happens outside the network perimeter. Operators need administrator access on a host first, and the credentials that provide it appear regularly in infostealer logs, leaked databases, and criminal marketplaces.

CloudSEK XVigil monitors deep, dark, and surface web sources for those organization-specific exposures. Resetting an exposed account closes the path long before anyone reaches the stage where credential dumping becomes possible.

Related Posts
What is Malware Sandboxing? How It Works and Its Limits
Malware sandboxing runs suspicious files in an isolated environment to observe their behavior safely. How malware sandboxing works, its types, and evasion.
What is Google Dorking? Operators, Risks, and Defense
Google dorking uses advanced search operators to find sensitive data exposed on the web. How it works, what it exposes, and how to defend against it.
6 Best Digital Risk Protection (DRP) Platforms in 2026
CloudSEK XVigil, Recorded Future, ZeroFox, Rapid7, Group-IB, and Flare cover key DRP needs across external risk, takedown, SOC workflows, scams, and illicit monitoring.

Start your demo now!

Schedule a Demo
Free 7-day trial
No Commitments
100% value guaranteed

Related Knowledge Base Articles

No items found.