Netskope Threat Labs

Mimikatz

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Mimikatz is a legitimate credential dumping tool that extracts passwords, hashes, and tickets from Windows memory, and cyberattackers frequently use it to harvest credentials after gaining a foothold. Its creator maintains it as a security research tool, and its techniques exposed weaknesses in Windows authentication that reshaped enterprise defense. Because it is a staple of post exploitation, defenders should alert on its behaviors and constrain where credential access tooling can run.

First seen
January 2022
Last seen
October 2026

17 techniques across 5 tactics.

TA0003 Persistence

  • T1098Account Manipulation
  • T1547Boot or Logon Autostart Execution

TA0005 Stealth

TA0006 Credential Access

TA0008 Lateral Movement

TA0112 Defense Impairment

  • T1207Rogue Domain Controller
Alert Name
Application.HackTool.Mimikatz.1
Application.HackTool.Mimikatz.5
Application.HackTool.Mimikatz.AE
Application.HackTool.Mimikatz.AF
Application.HackTool.Mimikatz.AG
Application.HackTool.Mimikatz.AI
Application.HackTool.Mimikatz.AQ
Application.HackTool.Mimikatz.O
Application.HackTool.Mimikatz.Q
Application.HackTool.Mimikatz.S