
Mimikatz
Mimikatz is a free Windows research tool for authorised Active Directory and lab credential assessments, widely taught in HTB Academy.
0 upvotes · 0 downvotes
No ratings yet
- Category
- Offensive Security & Pentesting
- Pricing
- Free
- Platforms
- Windows
- License
- Open source
- Reviewed
- Last reviewed 2 October 2026
- Links
- GitHub
What it is
Mimikatz is a free Windows security research utility by Benjamin Delpy (github.com/gentilkiwi/mimikatz). In authorised Active Directory assessments and training labs, including Hack The Box Academy Windows and AD modules, it demonstrates how credentials and authentication material can be recovered or abused when hosts are misconfigured or already compromised under rules of engagement.
What it helps with
- Illustrating LSASS and related credential-exposure risks on authorised Windows lab hosts.
- Supporting Kerberos and ticket-related exercises taught in AD attack-path courses and HTB Academy content.
- Helping blue and purple teams validate detection of credential-access techniques in controlled ranges.
- Complementing BloodHound, Impacket and NetExec-style tooling already used in authorised AD labs.
- Running from published source and builds maintained by the author for research and education.
- Documenting defensive hardening needs around credential guard, LSA protection and privileged access.
Who it's for
Penetration testers, AD lab students and defenders practising on HTB Academy and similar authorised Windows ranges who need the classic credential-research tool with clear permission boundaries.
Worth knowing
Mimikatz is free research software with public source on GitHub (gentilkiwi/mimikatz). Official mark: project mimikatz.ico / author branding. It is not malware packaging for criminal use; unauthorised use against systems you do not own or have written permission to test is illegal. Authorised penetration testing, research and lab use only.
Discussion & reviews
0 comments
No contributions yet. Be the first to review or comment.