Mimikatz hack tool dump pass from memory


hi there,

is there way protect winos against tool: http://blog.gentilkiwi.com/mimikatz (sorry in french first print screen relevant...)

according author (no ntlm, no admin /system/debug privilege, no local admins) in real life have grant users admin, , using tool right escalation may devastating can dump , reverse password stored in memory...

is there native way protect stuff except using strong authentication , uptodate av software ?

thanks feedback!

uac not protect you, because if tool can installed via an exploit. attacker launch privilige escalation attack.

possible solutions:

* keep server patched, can exploited

* if tool copied server, let av software remove automatically

* remove devops local admin group , assign them rights need


johan loos



Windows Server  >  Security



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Windows 2016 RDS event 1306 Connection Broker Client failed to redirect the user... Error: NULL

Como saber quien entro a mi PC por la Red