Skip to main content
39 entries found. Displaying page 1 of 2.
Updated on Jun 21, 2016

Mimikatz is a well-known hacktool used to extract Windows passwords in plain-text from memory, perform pass-the-hash attacks, inject code into remote processes, generate golden tickets, and more. This tool is used by red teams and real threat actors alike due to its powerful toolset and open-source nature allowing for easy modification. This tool is still regularly maintained and kept up to date with latest changes in Windows. Mimikatz is often delivered and executed without writing to disk (fileless) in an attempt to avoid detection. 

Alert level: high
Updated on Jul 05, 2018
Alert level: high
Updated on Sep 30, 2018
Alert level: high
Updated on Oct 19, 2018
Alert level: high
Updated on Oct 29, 2018
Alert level: high
Updated on May 24, 2019
Alert level: high
Updated on May 24, 2019
Alert level: high
Updated on Jul 09, 2019
Alert level: high
Updated on Jul 05, 2021
Alert level: high
Updated on Aug 03, 2022
Alert level: high
Updated on May 04, 2024
Alert level: high
Updated on Aug 14, 2020
Alert level: high
Updated on Jul 15, 2021
Alert level: high
Updated on Jan 19, 2023
Alert level: high
Updated on Oct 29, 2023
Alert level: high
Updated on Mar 07, 2015

Microsoft Defender Antivirus detects and removes this threat.

Hacktools can be used to patch or "crack" some software so it will run without a valid license or genuine product key.

We recommend you don't run hacktools because they can be associated with malware or potentially unwanted software.

We often see malware on PCs where hacktools are detected. You can read more about hacktools in Volume 13 of the Security Intelligence Report.

Alert level: high
Updated on Apr 11, 2017
Alert level: high
Updated on May 08, 2019
Alert level: high
Updated on May 08, 2019
Alert level: high
Updated on Feb 27, 2020
Alert level: high