Mimikatz hack tool dump pass from memory


hi there,

is there way protect winos against tool: http://blog.gentilkiwi.com/mimikatz (sorry in french first print screen relevant...)

according author (no ntlm, no admin /system/debug privilege, no local admins) in real life have grant users admin, , using tool right escalation may devastating can dump , reverse password stored in memory...

is there native way protect stuff except using strong authentication , uptodate av software ?

thanks feedback!

uac not protect you, because if tool can installed via an exploit. attacker launch privilige escalation attack.

possible solutions:

* keep server patched, can exploited

* if tool copied server, let av software remove automatically

* remove devops local admin group , assign them rights need


johan loos



Windows Server  >  Security



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Event ID 64,77,1008 Certificates Events Windows Server 2008, 2008R2