🚀 CloudSEK featured in the 2026 Frost Radar™!
Read more
Mimikatz is an open-source Windows tool that extracts authentication material from a system's memory, including plaintext passwords, NTLM hashes, PINs, and authentication tickets such as Kerberos tickets.
Attackers run the tool after they already hold administrator access on a host, then reuse the recovered credentials to authenticate elsewhere on the network.
Windows keeps credential material in memory, so users authenticate once and then access file shares, email, and applications without retyping passwords.Â
The tool exploits no vulnerability. It reads the same memory that single sign-on relies on, so patching alone never removed the risk.
Benjamin Delpy, a French security researcher known as gentilkiwi, wrote Mimikatz in C in 2007 to study how Windows handles credentials.
That first version targeted pass-the-hash techniques that were already well documented, and the project grew as Delpy mapped more of the authentication stack.
Delpy released the tool publicly as version 1.0 in 2011 and reported the underlying credential-storage weakness to Microsoft. Microsoft's position at the time was that the technique required an already compromised machine, so the behavior remained in place, and the tool continued to work across successive Windows releases.
Nearly two decades later, the project remains open source and actively developed. Anyone can compile it from source, rename it, or load it directly in memory, so blocking a single file hash accomplishes very little.
Mimikatz extracts credentials by reading the memory of the Windows process that stores authentication material for logged-on sessions, then decoding the structures it finds there.

The Local Security Authority Subsystem Service (LSASS) enforces local security policy, validates logons, and holds the secrets that make single sign-on possible. Each interactive logon, service account start, and scheduled task run leaves credential material in that process.
Every credential in LSASS belongs to a session that the operating system trusts. Mimikatz reads those structures directly and returns the secrets in a usable form.
Mimikatz requires local administrator or SYSTEM rights, since opening a handle to LSASS requires debug privilege.
Execution lands in the middle of an intrusion: after initial access through phishing, stolen credentials, or an exploited service, and before lateral movement across the domain.
Attackers split the operation into two whenever they want to avoid running the tool on the victim host. A signed Windows binary such as Task Manager, ProcDump, or rundll32 with comsvcs.dll writes an LSASS memory dump to disk.
Mimikatz then parses that dump later, on attacker infrastructure, far from the victim network.
Microsoft's security researchers documented this pattern because it defeats controls tuned to Mimikatz itself. The activity on the victim host looks like an administrator capturing a crash dump, while the credential extraction happens somewhere with no monitoring at all.
Mimikatz splits its capabilities into modules, and each module maps to a distinct defensive concern:
Module names carry detection value, a point covered in the detection section below. Red Canary reports that sekurlsa::logonpasswords stays the most observed module year after year, followed by ticket listing and SAM dumping.
Credential material recovered by Mimikatz feeds four attack techniques that authenticate without ever knowing a password, all catalogued in the MITRE ATT&CK framework.
An NTLM hash authenticates to any system that accepts NTLM, because the protocol treats the hash as the secret (T1550.002). Local administrator accounts sharing one password across many machines turn a single dumped hash into access across an entire estate.
Attackers inject stolen Kerberos tickets into a new logon session, then replay them against services until the tickets expire (T1550.003).
Overpass-the-hash converts a recovered NTLM hash or AES key into a valid ticket-granting ticket, upgrading a hash into full Kerberos access.
An account with directory replication rights asks a domain controller to send password data for any account, mimicking normal replication traffic between controllers (T1003.006).
One such request produces the KRBTGT hash and every user hash in the domain, without touching a single file on the controller.
A KRBTGT hash allows an attacker to forge ticket-granting tickets for any user, including accounts that never existed, which is the golden ticket attack (T1558.001).
Stolen service account hashes allow forged service tickets for a single service, known as silver tickets (T1558.002).
Forged tickets survive password resets on the compromised user accounts, so recovery requires rotating the KRBTGT account twice. Mapping the resulting access across systems is where an attack path view helps responders see how far one dumped hash reaches.
Joint government advisories place Mimikatz inside ransomware operations that agencies actively investigate. The FBI, CISA, and Australian Signals Directorate advisory on Play ransomware documents the group using Mimikatz to obtain domain administrator credentials.
Its June 2025 update recorded approximately 900 affected entities as of May 2025, three years after the group first appeared.
A multi-agency update to the Akira ransomware advisory in November 2025 described the same credential-dumping stage, including extraction from LSASS dump files. Closed operations such as SafePay follow the same sequence with different tooling, which makes credential theft a shared checkpoint across ransomware campaigns.
NotPetya remains the most destructive example of Mimikatz-derived code inside a self-spreading payload. The 2017 wiper carried a credential stealer built on that code alongside exploit-based spreading.
Harvested passwords let the malware reach machines that were fully patched, because valid credentials need no vulnerability.
State-sponsored groups adopted the tool for the same reason criminal operators did. Public reporting ties Mimikatz to dozens of tracked intrusion sets, where it appears mid-campaign during the credential access stage of an advanced persistent threat operation.
Yes, Mimikatz still works, though modern Windows defaults block its most direct techniques on hardware that supports them.
Coverage gaps remain wide across real estate, for reasons that have nothing to do with the features themselves. Older servers, workgroup machines, and virtual desktops without the required hardware all leave LSASS readable.
Devices upgraded from earlier builds with the features explicitly disabled remain in the same position. Attackers holding SYSTEM rights load signed vulnerable drivers to strip process protection where it is enabled.
Kerberos abuse survives all three controls because forged tickets need no access to LSASS memory. Credential Guard protects secrets on the host, and a golden ticket forged from a stolen KRBTGT hash still authenticates normally.
To detect Mimikatz, security teams monitor process access to LSASS, command-line arguments containing module names, and the artifacts the tool leaves behind, because file signatures alone miss recompiled and in-memory variants.
Module strings such as sekurlsa::logonpasswords, sekurlsa::tickets, sekurlsa::ekeys, and lsadump::sam appear in process command lines and PowerShell script block logs.
PowerShell wrappers add their own signals. Red Canary identifies Invoke-Mimikatz with a credential-dumping parameter as the most common execution method in its telemetry.
Sysmon Event ID 10 records which process opened a handle to lsass.exe and with what access rights. The access-rights combinations used for memory reading stand out against normal activity.
Windows Security auditing produces equivalent visibility through object access events, once a system access control list is configured on the LSASS process.
Signed Microsoft binaries deserve the same scrutiny as unknown executables here. Dump creation through ProcDump, Task Manager, or rundll32 calling comsvcs.dll MiniDump generates LSASS access from tools that administrators rarely aim at that process.
Kerberos ticket files carry the .kirbi extension, and Red Canary recommends alerting on their creation because exported tickets precede replay attacks. Large dump files written to temporary directories point to the offline extraction path.
Authentication telemetry closes the loop once stolen credentials leave the host. A workstation that suddenly authenticates as several privileged accounts, or a service account logging on interactively for the first time, indicates that dumped credentials are already in use and belongs in security monitoring rules.
Red team exercises and control validation generate a large share of real-world Mimikatz alerts. Red Canary's analysis found that removing customer-confirmed testing dropped Mimikatz from affecting 7.2% of monitored customers to 3.1%.
Its analysts assessed that even the remaining ranking stayed inflated by testing nobody reported.
Alert triage for this tool starts with attribution, not severity. A SOC that maintains a current register of authorized testing, scoped hosts, and test windows resolves these alerts in minutes.
Teams without that register treat every simulation as an active intrusion, and lose the hours they need for the real ones.
Defense against Mimikatz works by removing credentials from memory, restricting where privileged accounts log on, and detecting the reuse that follows a successful dump.
Legality turns entirely on authorization. Possession and study of Mimikatz stay lawful in most jurisdictions, and running it against systems without permission constitutes unauthorized access under computer misuse law.
Internal policy sets the practical boundary for most enterprise security teams. Many organizations require named approval, defined hosts, logging, and time windows before any credential-dumping tool runs, and classify malware-adjacent tooling under the same change controls.
What does the name Mimikatz mean?
Mimikatz comes from French slang for cute cats, chosen by its author Benjamin Delpy, whose online handle gentilkiwi follows the same playful naming style.
Does Mimikatz work on Linux or macOS?
No. Mimikatz targets Windows authentication components, though tools such as Impacket run comparable credential attacks against Windows systems from Linux hosts.
Can Windows Defender detect Mimikatz?
Yes, for the standard binary. Recompiled, renamed, or reflectively loaded variants evade signature detection and require behavioral rules on LSASS access.
Does Mimikatz bypass multi-factor authentication?
In effect, yes. Reused hashes and Kerberos tickets authenticate at the protocol level, skipping the interactive sign-in flow where MFA is enforced.
What is the difference between Mimikatz and Impacket secretsdump?
Mimikatz extracts credentials from memory on a compromised host. Impacket secretsdump pulls SAM, LSA, and NTDS secrets remotely over the network.
Is Mimikatz classified as malware?
Security vendors flag it as a hacktool or riskware. Its author built it for research, and threat actors use the same builds during intrusions.
CloudSEK does not detect Mimikatz execution on an endpoint. That job belongs to EDR and identity threat detection tooling watching LSASS access and authentication behavior inside the network.
Everything that precedes the dump happens outside the network perimeter. Operators need administrator access on a host first, and the credentials that provide it appear regularly in infostealer logs, leaked databases, and criminal marketplaces.
CloudSEK XVigil monitors deep, dark, and surface web sources for those organization-specific exposures. Resetting an exposed account closes the path long before anyone reaches the stage where credential dumping becomes possible.
