Catalog WADComs

WAD · Tool

Pypykatz

1 technique Linux · ActiveDirectory · WindowsWADComs GPL-3.0

Pypykatz-Minidump

NEW
Credential Access LinuxActiveDirectoryWindows

Pypykatz is a pure-Python reimplementation of Mimikatz's sekurlsa module that parses an LSASS minidump entirely offline, so credentials can be extracted on the operator's Linux box without running Mimikatz on the target. Feed it any dump produced by nanodump, comsvcs.dll MiniDump, or procdump to recover NT hashes, Kerberos keys, and cached plaintexts. This keeps the noisy parsing off the victim host and out of reach of host EDR. Command Reference: Input dump: lsass.dmp Output file: output.txt

pypykatz lsa minidump lsass.dmp -o output.txt
Native
Credential Access
Requires
Shell
Services
NTLM, Kerberos