All tools

Post-Exploitation

Mimikatz

Extracts credentials, tickets, and secrets from Windows memory/LSASS.

intermediate
Windows
Post-Exploitation
Lateral Movement

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

When

High-privilege access on Windows lab machines to demonstrate credential theft.

How

privilege::debug; sekurlsa::logonpasswords; careful OPSEC in real envs.

Why

Teaches why credential hygiene and Credential Guard matter.

Commands & usage

privilege::debug
sekurlsa::logonpasswords
lsadump::sam
kerberos::list /export

Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.

Tags

credentials
windows
memory

Related in Post-Exploitation