EC-Council Certified Ethical Hacker (CEH) v12System Hacking Phases and Attack TechniquesHard

A penetration tester is aiming to perform credential dumping on a Windows domain controller. They have gained local administrator access to the DC and are now considering tools and techniques to extract password hashes. Which of the following tools is specifically designed and commonly used for this purpose on Windows systems?

  1. AMimikatz
  2. BNmap
  3. CMetasploit Framework (without specific modules)
  4. DWireshark
Show answer & explanation

Correct answer: A. Mimikatz

Mimikatz is a powerful and widely-known post-exploitation tool specifically designed to extract plaintext passwords, hash, PIN codes, and Kerberos tickets from memory on Windows systems, making it ideal for credential dumping on a domain controller.

Why the other options are wrong

  • B. Nmap is a network scanner used for discovery and vulnerability mapping, not credential dumping.
  • C. While Metasploit Framework has modules that can perform credential dumping (often integrating Mimikatz functionality), 'Metasploit Framework' itself is too general; Mimikatz is the specific tool for the task.
  • D. Wireshark is a packet analyzer used for network traffic inspection, not for extracting credentials directly from memory.

Credential Dumping (Mimikatz)

Credential dumping is the process of extracting user logon credentials (e.g., password hashes, plaintext passwords, Kerberos tickets) from a compromised system's memory or storage.

  • Mimikatz is a primary tool for this on Windows systems.
  • Often targets the Local Security Authority Subsystem Service (LSASS) process.
  • A critical step for lateral movement and privilege escalation in Active Directory environments.

Memory trick: Memory holds secrets, Mimikatz reveals them!

More System Hacking Phases and Attack Techniques questions