Mimikatz hack tool dump pass from memory
hi there,
is there way protect winos against tool: http://blog.gentilkiwi.com/mimikatz (sorry in french first print screen relevant...)
according author (no ntlm, no admin /system/debug privilege, no local admins) in real life have grant users admin, , using tool right escalation may devastating can dump , reverse password stored in memory...
is there native way protect stuff except using strong authentication , uptodate av software ?
thanks feedback!
uac not protect you, because if tool can installed via an exploit. attacker launch privilige escalation attack.
possible solutions:
* keep server patched, can exploited
* if tool copied server, let av software remove automatically
* remove devops local admin group , assign them rights need
johan loos
Windows Server > Security
Comments
Post a Comment