S0002: Mimikatz
Mimikatz is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along with many other features that make it useful for testing the security of networks. CitationDeply Mimikatz CitationAdsecurity Mimikatz Guide
Security context for executives and security teams
Mimikatz matters because it turns a Windows compromise into an identity compromise. ATT&CK describes it as a credential dumper capable of obtaining plaintext Windows account logins and passwords, and the relationship set shows it has been used across many named campaigns and groups. For leaders, the practical issue is not the tool alone; it is whether Windows credentials, privileged accounts, and lateral movement paths are protected well enough that one endpoint incident does not become an enterprise-wide access problem.
Executive priority
Prioritize Mimikatz-related readiness as an identity resilience and incident-response decision point. Executives should ask whether the organization can prove where Windows credentials are exposed, how privileged account use is limited, and whether SOC and IR teams can rapidly identify and contain credential dumping activity. The broad ATT&CK relationship context, including espionage, ransomware, supply chain, government, critical infrastructure, and safety-system-adjacent campaigns, makes this a control-validation priority for business continuity, audit evidence, and crisis response planning.
Technical view
The supplied ATT&CK object identifies Mimikatz as a Windows tool for dumping credentials, but provides no official detection logic or tactics. SOC and detection teams should therefore validate coverage around Windows credential access behaviors, suspicious credential-dumping tool presence, execution of known Mimikatz-related binaries or command patterns where locally available, abnormal access to credential material, and post-compromise use of harvested accounts. IR teams should treat confirmed Mimikatz presence as a trigger to investigate credential exposure scope, privileged account use, lateral movement, and password/session/token remediation requirements.
Likely telemetry
- Windows endpoint process execution and command-line telemetry
- Endpoint security alerts for credential dumping or known Mimikatz tooling
- Windows security logs related to logon activity, privileged account use, and authentication anomalies
- File creation, module load, and memory-access telemetry from protected Windows systems where available
- Identity provider, domain controller, and authentication logs for downstream use of potentially stolen credentials
Detection direction
- Do not rely only on tool-name or hash detection; Mimikatz is publicly available and may be renamed or modified.
- Validate whether endpoint telemetry captures process execution, command lines, credential-store access indicators, and suspicious privileged activity on Windows systems.
- Correlate suspected credential dumping with subsequent authentication from unusual hosts, new administrative access, or lateral movement patterns.
- Tune detections against legitimate security testing activity, since the official description notes Mimikatz is also useful for testing network security.
- Use the relationship context to test detections against realistic intrusion scenarios where credential dumping follows initial compromise and precedes broader access.
Mitigation priorities
- Reduce credential exposure on Windows systems by hardening privileged access and limiting where high-value accounts can log on.
- Enforce least privilege and separate administrative accounts from routine user activity.
- Prepare incident playbooks that include credential invalidation, password resets, session/token review, and privileged account containment after confirmed credential dumping.
- Use managed detection or internal SOC validation to confirm that Windows endpoint and identity telemetry is collected, retained, and correlated.
- Include Mimikatz-style credential dumping in tabletop exercises and control testing because ATT&CK links this tool to numerous campaigns and groups.
Additional notes and limits
ATT&CK does not provide official detection text for this object and does not specify tactics in the supplied fields. The strongest decision value comes from the tool description, the Windows platform designation, and the extensive relationship context showing use by multiple campaigns and groups, including Operation Wocao, C0017, AvosLocker-related C0018, SolarWinds Compromise, Triton-related campaigns, HomeLand Justice, SharePoint ToolShell Exploitation, Operation Digital Eye, and many named threat groups.
This take is limited to the supplied ATT&CK fields, external references, and relationships. It does not assert current exploitation, customer exposure, specific detection coverage, or detailed procedure-level behavior beyond the official description. Local validation is required to determine actual telemetry availability, compensating controls, and credential exposure risk.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Mimikatz
Mimikatz is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along with many other features that make it useful for testing the security of networks. CitationDeply Mimikatz CitationAdsecurity Mimikatz Guide
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
All related ATT&CK context
No relationships are available in the current normalized data for this object.
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
