MimiKatz,Kiwi

#kiwi

  • In the meterpreter session load Kiwi

load kiwi
help
  • Retrieve all credentials

Copy

  • Dump LSA SAM (NTLM hashes for all users)

#Hash Dumping - Mimikatz.exe

  • Run mimikatz.exe

  • Dump the cache of the lsass process

  • Display logon passwords, when stored in clear-text

    • in this case clear-text password are disabled - (null)

Last updated