Overview
Mimikatz (MITRE ATT&CK ID S0002) is a credential dumper capable of obtaining plaintext Windows account logins and passwords, per MITRE’s software profile, “along with many other features that make it useful for testing the security of networks.” Like Cobalt Strike and Empire, Mimikatz is a legitimate security-testing tool that is also one of the most extensively documented dual-use utilities in MITRE’s knowledge base.
Actors documented using this tool (per MITRE ATT&CK relationship data)
Our ingested data links Mimikatz to over 50 distinct MITRE ATT&CK groups — the widest usage of any entity in this batch — including APT38, Indrik Spider, Kimsuky, Volt Typhoon, APT41, APT32, Sandworm Team, Mustang Panda, OilRig, Turla, APT29, APT28, LAPSUS$, and Wizard Spider, spanning nation-state espionage groups, financially motivated crime crews, and ransomware operators alike.
Notable techniques (per MITRE ATT&CK relationship data)
Techniques MITRE links to Mimikatz in our data include Account Manipulation (T1098), Credentials from Password Stores (T1555), Credentials from Web Browsers (T1555.003), DCSync (T1003.006), Golden Ticket (T1558.001), LSA Secrets (T1003.004), LSASS Memory (T1003.001), and Pass the Hash (T1550.002) — the last two among the most common real-world Windows credential-theft techniques documented in ATT&CK overall.
What we don’t have
MITRE’s ingested data doesn’t include a discovery/first-observed date for software entries. We have no independent telemetry beyond MITRE’s STIX bundle, and given Mimikatz’s status as a widely distributed, publicly available tool, no way to distinguish which specific build or fork any individual documented use involved.
Frequently Asked Questions
What is Mimikatz? A credential-dumping tool, per MITRE ATT&CK, that extracts plaintext Windows passwords and supports techniques like Pass the Hash and Golden Ticket attacks — legitimately used for security testing but extensively repurposed by threat actors.
How widely is Mimikatz used by threat actors? Per MITRE ATT&CK’s relationship data, over 50 distinct tracked groups are documented as using it — the broadest usage of any tool or malware family in our ingested MITRE data.
What techniques does Mimikatz enable? Per MITRE ATT&CK’s relationship data: LSASS memory credential extraction, Pass the Hash, Golden Ticket (Kerberos) attacks, and DCSync, among others.
Data sourced from MITRE ATT&CK® (https://attack.mitre.org), software ID S0002, aggregated August 29, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more malware profiles.