Mimikatz
Windows security tool that extracts plaintext passwords, hashes, PINs and Kerberos tickets from memory.
External Tool
This open-source tool is maintained externally. View the source on GitHub to learn more or run it yourself.
Browse security tools →What's next with Mimikatz?
Choose how you want to get started.
Use it free
Open the official tool or demo — no account needed.
Self-host it
Run the open-source version on your own infrastructure.
What is Mimikatz?
Mimikatz is an open-source Windows security tool developed for learning and experimenting with Windows authentication mechanisms. It enables security researchers, penetration testers, and IT professionals to analyze how credentials, hashes, and security tokens are stored and processed in memory. The tool addresses the challenge of understanding Windows security vulnerabilities by providing a way to extract plaintext passwords, Kerberos tickets, and other sensitive data from memory. Its primary users include ethical hackers and system administrators who need to test the resilience of Windows environments against credential theft attacks. By simulating real-world attack scenarios like pass-the-hash or Golden ticket creation, Mimikatz helps identify weaknesses in authentication protocols and privilege escalation techniques.
How it works
Mimikatz was originally created by Benjamin DELPY (gentilkiwi) as a personal project to explore Windows security and practice C programming. It has since evolved into a widely recognized tool for analyzing Windows security mechanisms, particularly focusing on credential handling and authentication protocols. The tool's purpose is to provide a hands-on way to study how Windows stores and processes sensitive information such as passwords, PIN codes, and Kerberos tickets. It serves as both an educational resource and a practical tool for security testing. Mimikatz can extract plaintext passwords, NTLM hashes, Kerberos tickets, and PIN codes from memory. It also supports advanced techniques like pass-the-hash, pass-the-ticket, and Golden ticket creation. For example, the command 'sekurlsa::logonpasswords' retrieves credentials from the LSASS process, while 'kerberos::list' displays Kerberos tickets stored in memory.
How to use it
- 1Launch Mimikatz with administrative privileges to access memory data. 2. Use 'privilege::debug' to enable debugging privileges. 3. Execute 'sekurlsa::logonpasswords' to dump credentials from LSASS. 4. Run 'kerberos::list' to view Kerberos tickets stored in memory. Practical tips include using the 'token::elevate' command to escalate privileges and the 'vault::list' module to access cryptographic keys. Ensure compatibility with the target Windows version and use the 'mimikatz.exe' binary for 32-bit or 64-bit systems. Avoid running in environments with strict security monitoring to prevent detection.
What it can do
- Windows credential extractor
Use cases
Assumptions and limitations
Assumptions
- source: https://github.com/gentilkiwi/mimikatz
- license: CC BY 4.0 — free to use
- privacy: Self-hosted — you control your data
Limitations
- Limited to Windows environments and requires direct access to the target system
- Depends on elevated privileges to access sensitive memory data
- May trigger antivirus or endpoint detection systems due to its malicious-like behavior
- Lacks a graphical user interface, requiring command-line expertise
- Incompatible with newer Windows versions due to kernel changes
Understanding the result
Windows security tool that extracts plaintext passwords, hashes, PINs and Kerberos tickets from memory.
Tool details
- Clearly flagged when a network request is needed.
- No account, no sign-up, and no tracking of your content.
- Powered by (MIT).
- Built with
- (gentilkiwi/mimikatz)
- License
- MIT
- Runs locally
- No — requires a network request
- Verification
- Not yet verified
- Input
- Query
- Output
- Text
Built with gentilkiwi/mimikatz. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.
- Built with
- License
- MIT
Open-source project
OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.
References
- / — GitHub Repository
Upstream project · GitHub
- CC BY 4.0 License
Upstream project
Frequently asked
What is Mimikatz and what does it do?
Mimikatz is an open-source Windows security tool designed for learning and testing Windows authentication mechanisms. It extracts plaintext passwords, hashes, PIN codes, and Kerberos tickets from memory, enabling users to analyze how credentials are stored and used. It also supports techniques like pass-the-hash and Golden ticket creation, making it a critical tool for understanding Windows security vulnerabilities.
How does Mimikatz extract credentials from memory?
Mimikatz uses Windows security APIs to access the Local Security Authority Subsystem Service (LSASS) process, where credentials are stored in memory. Commands like 'sekurlsa::logonpasswords' dump credentials by reading the LSASS memory space. It also leverages the Kerberos protocol's ticket storage to retrieve authentication tokens, allowing analysis of how Kerberos tickets are used for network authentication.
How do I use Mimikatz to dump credentials?
Launch Mimikatz with administrative privileges. First, run 'privilege::debug' to enable debugging privileges. Then, execute 'sekurlsa::logonpasswords' to extract credentials from LSASS. For Kerberos tickets, use 'kerberos::list' to view stored tickets. To escalate privileges, use 'token::elevate' after gaining initial access.
How does Mimikatz compare to other security tools?
Mimikatz is unique in its focus on Windows credential extraction and Kerberos ticket analysis, unlike tools like PowerShell or Mimikatz alternatives such as Empire. While Empire is a post-exploitation framework, Mimikatz specializes in memory-based credential harvesting. It is also distinct from tools like pwdump, which rely on extracting hashes from SAM databases rather than memory.
What should I do if Mimikatz fails to dump credentials?
Common issues include insufficient privileges, antivirus interference, or incompatible Windows versions. Ensure you run Mimikatz with administrative rights and disable real-time protection temporarily. If the target system uses Windows 10/11, check for kernel changes that may affect LSASS access. Use the 'mimikatz.exe' binary compatible with the target architecture (32-bit or 64-bit).