All tools
Post-Exploitation
Mimikatz
Extracts credentials, tickets, and secrets from Windows memory/LSASS.
intermediate
Windows
Post-Exploitation
Lateral Movement
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
When
High-privilege access on Windows lab machines to demonstrate credential theft.
How
privilege::debug; sekurlsa::logonpasswords; careful OPSEC in real envs.
Why
Teaches why credential hygiene and Credential Guard matter.
Commands & usage
privilege::debug
sekurlsa::logonpasswords
lsadump::sam
kerberos::list /export
Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.
Tags
credentials
windows
memory