I Used Mimikatz on Our Own Network and Found Dozens of Plaintext Passwords in Memory—A Case Study

How quickly can a single exposed service let attackers turn one login into full domain control? That question drove a controlled validation on our Windows estate. We mimicked real-world moves where threat actors abuse exposed Remote Desktop Protocol (RDP), drop an archive with Process Hacker and a credential-dumping tool, then scrape memory for secrets.

Table of contents

An expert take by Ethan Cross, HakTechs.com Lead Analyst

We targeted an unprotected server—no VPN, no rate limiting, no multi-factor authentication (MFA). Attackers gained admin creds and moved laterally across the network in minutes. Endpoints guarded by modern EDR blocked the payload and stopped spread.

This defensive exercise revealed where credentials and password material accumulate in memory, why legacy AV misses the behavior, and what teams must monitor now.

For techniques and Windows details on how credentials live in memory, see LSA and credential notes. This work aims to help security teams spot blind spots and harden environments before real attacks exploit them.

Key Takeaways

  • One exposed RDP host can let attackers harvest credentials and pivot fast.
  • Memory often holds multiple credential types; monitor process behavior, not just files.
  • Modern EDR that blocks memory scraping can stop these attacks when tuned correctly.
  • Legacy AV and whitelisted RDP traffic create dangerous blind spots.
  • Controlled validation on live systems gives the clearest view of real risks.

Why We Ran a Live Test in a Windows Environment

Our team simulated real attacker steps on an operational Windows domain to capture credential-handling signals. The aim was to observe how credential dumping appears in processes, logs, and registry-backed caches so teams can tune detection and response.

Credential theft is a common step in lateral movement. Windows stores secrets across SAM, cached credentials, LSA secrets, and the LSASS process. These places can contain plaintext, NT/LM hashes, and Kerberos tickets.

We tracked where credentials live and what alerts they create. Live validation reveals process reads, Event ID 4688 trails, and shadow copy activity that tabletop exercises miss. After initial access, attackers often steal credentials, copy payloads via PsExec or SMB, run remote binaries, and repeat.

Tests stayed scoped: no destructive actions, focused on evidence from LSASS memory and registry caches. Using open source tools helped us map behaviors defenders should detect, not just filenames.

Location Artifact Common Signals Suggested Detection
SAM / Registry Cached hashes Registry reads, vssadmin use Monitor registry access, limit shadow copies
LSASS memory Plaintext / NTLM hashes / tickets Process read attempts, LSASS tamper alerts EDR LSASS protections, alert on unusual handles
Kerberos Tickets Ticket reuse, abnormal Kerberos requests Detect ticket anomalies, restrict delegation
Network shares Copied payloads PsExec, SMB transfers, 4688 events Harden file shares, log remote execution
A dark, dimly-lit Windows desktop with a glowing terminal window in the foreground, displaying lines of telemetry data and memory credentials. In the middle ground, a network diagram with interconnected nodes, cables, and security icons. The background is hazy, with an ominous, shadowy atmosphere, suggesting the gravity of the security vulnerability uncovered. The lighting is dramatic, casting dramatic shadows and highlights, creating a sense of tension and urgency. The overall scene conveys the technical depth and high-stakes nature of the investigation described in the article's section.

Outcome: a clearer map from initial access to credential dumping and lateral execution, enabling security and IT teams to validate alerts and close blind spots.

A Case Study of Using Mimikatz to Find Plaintext Passwords

Our team examined LSASS on running hosts to catalog live credential material held in memory. This short, focused validation shows what lives inside the local security authority while users and services are active.

A dark, shadowy process emerges from the depths of a computer's memory, its tendrils reaching out to extract sensitive information. The lsass process, a core component of the Windows operating system, is the target of the notorious Mimikatz tool, exposing plaintext passwords hidden within its digital footprint. Harsh, dramatic lighting illuminates the intricate details of this malicious process, casting an ominous atmosphere that underscores the gravity of the security breach. The scene is captured through a high-resolution lens, showcasing the technical complexity and the potential for exploitation within this vulnerable system component.

How the tool interacts with the service matters more than the filename it runs from. Mimikatz hooks the security authority subsystem and reads process memory from the authority subsystem service (LSASS). That access exposes active authentication artifacts that enable replay and impersonation.

  • Secrets recoverable: plaintext passwords via WDigest/TSPkg/LiveSSP, NT/LM hashes, Kerberos tickets, and sometimes PIN codes stored for convenience.
  • Session behavior: credentials memory is tied to active logons; interactive and service sessions populate LSASS and logoff usually clears live material, though residues can remain.
  • Beyond dumping: the tool supports pass-the-hash, pass-the-ticket, and Golden Tickets, turning extracted artifacts into lateral movement and domain escalation.

Controls to reduce risk: validate that WDigest’s UseLogonCredential is disabled, enforce least privilege, and avoid interactive logons for high-value accounts. Monitor memory read patterns against the lsass process rather than chasing specific tool names.

Attack Path We Simulated and Observed in the Past

We recreated an end-to-end intrusion to show how one exposed entry point lets attackers escalate and spread within an environment. The timeline highlights where defenders should focus telemetry and controls.

The intrusion started when repeated RDP login retries hit an exposed admin server without MFA.

Initial access via RDP and brute force behavior on exposed services

High-volume RDP brute forcing targeted Patient-0 from unknown internet IPs. The host lacked VPN-only access, rate limiting, and multi-factor protection, so the attacker gained interactive access after repeated attempts.

Dropping open source tools: Mimikatz alongside Process Hacker

Once interactive, the intruder transferred an encrypted archive over the legitimate RDP session. The archive held Process Hacker and an open source credential tool, delivered to blend in with standard admin activity.

Pivoting and lateral movement with valid credentials across the network

Local admin rights let the actor extract credentials, then authenticate into additional hosts via RDP. Repeated remote sessions and remote execution mimicked normal workflows, enabling rapid lateral movement within network segments.

Bypassing legacy AV and “living off the land” techniques

Legacy AV missed the behavior because RDP traffic was whitelisted and signature checks don’t catch memory scraping. Behavioral EDR, however, detected suspicious process lineage and memory reads, quarantining the payload and stopping further spread.

  • Telemetry to capture: failed and successful RDP logons, rapid cross-host authentications, unusual process spawns, and account lockouts.
  • Residual risk: one harvested hash or ticket can enable follow-on access if segmentation and monitoring are weak.
A dense, interconnected network of attack paths, nodes, and memory segments visualized in a highly technical, schematic style. The foreground depicts a complex web of data flows, memory addresses, and security vulnerabilities, rendered in shades of blue, green, and red. The middle ground showcases individual memory segments, each containing sensitive information such as plaintext passwords, access tokens, and other privileged data, illuminated by a focused, dramatic lighting. The background features a dark, ominous backdrop, suggesting the gravity and potential consequences of the exposed attack surface. The overall composition conveys a sense of technical depth, urgency, and the need for comprehensive security measures.

What We Found in Memory: Credentials, Tickets, and Hashes

Our live memory snapshot exposed multiple active secrets inside the LSASS process during routine interactive sessions. The capture confirmed plaintext credentials, numerous hashes, and reusable Kerberos tickets that attackers could leverage immediately.

A dimly lit computer screen displaying the LSASS (Local Security Authority Subsystem Service) process, its intricate details and technical specifications visible. The process appears to be running, with data streams and memory allocations visible. The scene conveys a sense of exploration and investigation, as if the viewer is delving into the innerworkings of a complex system. Subtle lens flare and depth of field effects create a sense of depth and atmosphere, drawing the viewer's attention to the core of the LSASS process. The overall mood is one of technical fascination and a desire to uncover the secrets hidden within the system's memory.

Key findings:

  • Dozens of plaintext credentials were visible when WDigest was enabled or when services cached logon material. These items were tied to interactive sessions.
  • We recorded many NT/LM hashes. Each hash can enable pass-the-hash authentication across hosts without the original password string.
  • Kerberos tickets in memory allowed short-term impersonation. With domain controller access and NTDS.DIT extraction via shadow copies, attackers can move toward forging golden tickets.
  • Background services sometimes kept credential artifacts after logoff, extending exposure within network segments and helping an intruder move laterally.

Defensive notes: reduce what LSASS holds, validate WDigest is disabled, confirm Credential Guard, and alert on pass-the-hash and anomalous Kerberos tickets. For further technique details, see this advanced credential dumping write-up.

Detection, Containment, and Forensics Signals

Spot behavior that indicates credential theft and act fast to contain lateral spread. Focus on memory reads, suspicious process chains, and shadow copy activity to prioritize response.

The clearest early signals come from process-level reads against LSASS and unusual execution chains. These signs matter more than file names for reliable detection.

EDR alerts and suspicious process creation

Watch for direct handles on the lsass process and unusual child processes. Prioritize behavior-based alerts that flag attempts to read or dump the lsass process. Blocked PowerShell scripts that fetch open source tools from the internet should raise immediate suspicion.

Event and telemetry clues

Monitor Event ID 4688 for strange chains: PowerShell spawning unsigned binaries, archive utilities running from temp, or PsExec calls. Track vssadmin activity; shadow copy creation often precedes directory extraction.

Domain controller targeting

NTDS.DIT, SAM, and SYSTEM hive access usually follows shadow copy use. Look for volume shadow copy manipulation and psexecsvc.exe service creation on remote hosts.

  • Containment: isolate hosts, stop malicious processes, rotate exposed credentials.
  • Forensics: collect volatile memory and export logs before remediation steps alter evidence.
  • Validation: run safe simulations to confirm alerts for LSASS tampering and PsExec abuse.
Signal Indicator Recommended action
LSASS handles EDR tamper alert, abnormal process read Quarantine host, capture memory, alert SOC
Process creation Event ID 4688 showing PowerShell → unsigned binary Block binary, investigate parent process, hunt lateral traces
Shadow copy vssadmin list/create and NTDS access Lock down VSS, snapshot evidence, revoke credentials
Remote exec PsExec usage, psexecsvc.exe on targets Disable service, scan for further access, escalate containment
A close-up view of the Windows lsass.exe process, illuminated by a dim, eerie glow. The process window hovers in the foreground, its edges sharply defined, casting long shadows across a darkened, moody backdrop. The process interface is displayed in high contrast, highlighting intricate technical details and system metrics. A sense of digital forensics and cybersecurity investigation permeates the scene, the lsass process standing as a focal point for uncovering vulnerabilities and extracting sensitive information. The lighting is somber, creating an atmosphere of tense discovery, as if peering into the heart of a compromised system.

Hardening Against Credential Theft in Windows Operating Systems

Lock down remote administration first; public-facing logons give attackers the shortest path to credentials. Reduce exposure, and combine policy with behavior-based detection to raise cost for attackers.

Start by treating every remote login as high risk and assume credentials in memory are valuable targets.

Reduce exposed services and enforce stronger access

Remove public RDP where possible. Place remaining admin access behind VPN and require multi-factor authentication (MFA).

Apply rate limits and account lockouts to frustrate brute force. These steps cut the easiest paths attackers use to move laterally.

Limit privileged session exposure

Avoid interactive logons with domain or tier-0 accounts on shared hosts. That prevents high-value secrets from populating the local security authority or the lsass process on internet-facing systems.

Use Credential Guard, LAPS, and cached credential limits

Enable Credential Guard where supported to isolate the security authority subsystem and protect the authority subsystem service from direct memory reads.

Standardize unique local admin passwords with Microsoft LAPS, rotate them, and reduce cached domain logons to lower reuse risk. Strong password policies increase cracking time if hashes are exfiltrated.

Detect behavior, not just tool names

Block suspicious memory reads to sensitive processes and watch for remote execution patterns like PsExec and shadow copy manipulation.

Focus detection on process-level behavior so open source tools and renamed binaries cannot hide attacks. Segment admin tiers and use just-in-time access to shorten credential utility.

Control What it protects Action
RDP restrictions Public exposure, brute force Remove public RDP, VPN + MFA, rate limits
Credential Guard LSASS process, memory scraping Enable on supported systems, validate isolation
Microsoft LAPS Local admin credential reuse Unique passwords, regular rotation
Behavior detection Tool-agnostic attacks Alert on LSASS handles, remote exec, shadow copies
A dark, high-contrast scene depicting the hardening of a Windows operating system's local security. In the foreground, a desktop computer running Windows, its screen displaying a command prompt with security-related commands. The desktop is illuminated by the glow of the monitor, casting dramatic shadows. In the middle ground, various security tools and applications are open, such as the Windows Security app, Group Policy Editor, and a network monitoring tool. The background is shrouded in shadows, suggesting the seriousness and technical complexity of the task at hand. The overall atmosphere is one of focused determination, with the goal of strengthening the system's defenses against potential credential theft.

Operate defensively as a habit: run controlled simulations to confirm alerts for LSASS tampering and PsExec abuse, educate admins on risky login habits, and treat hardening as ongoing work to reduce drift.

Conclusion

The experiment proved that simple remote access paths often yield the richest rewards for malicious actors.

Live validation revealed plaintext and hashed credentials in memory that could enable rapid lateral movement across a Windows network.

Central finding: during controlled testing we observed credentials and tickets exposed in process memory, enabling quick access and follow-on attacks.

Practical steps: close unnecessary admin exposure, enforce MFA and rate limits, and deploy behavior-driven EDR that flags LSASS tampering and unusual Event ID 4688 chains.

Quick wins include disabling plaintext caching, enabling Credential Guard where supported, and rolling unique local admin secrets with LAPS. Watch for shadow copy activity and registry hive access that may precede NTDS.DIT theft on a domain controller.

Map current detections against these techniques, fix gaps, and re-test regularly. For additional field notes and an attack write-up, see this detailed write-up.

FAQ

Why run a live test in a Windows environment?

Running an authorized live test shows real-world exposure of credentials in memory, reveals how LSASS (Local Security Authority Subsystem Service) stores secrets, and validates detection and containment controls. It clarifies risk from exposed services like RDP and helps prioritize mitigations such as multifactor authentication and rate limiting.

What can tools extract from a running Windows system?

Open-source utilities can reveal plaintext secrets, NT/LM hashes, PIN codes, and Kerberos tickets held in process memory. When protections are absent, tools accessing LSASS can present credentials that enable lateral movement and reuse across the domain.

Why do plaintext credentials appear in memory?

Legacy authentication packages and in-memory subsystems such as WDigest, TSPkg, or LiveSSP may retain cleartext or reversible data. Applications and older Windows components sometimes cache or handle passwords in memory for single sign-on or backward compatibility, increasing exposure.

How do attackers typically gain initial access for credential theft?

Common paths include exposed RDP endpoints, password-spraying and brute-force attempts against online services, phishing that captures credentials, and exploitation of unpatched services. Once a foothold exists, attackers deploy tools or leverage built-in utilities to extract secrets from memory.

Which artifacts indicate credential dumping or LSASS tampering?

Look for suspicious process creation events (Event ID 4688), unexpected child processes of LSASS, use of tools like Process Hacker or credential dumpers, and EDR alerts on memory read or handle duplication against LSASS. System calls to create shadow copies or attempts to access NTDS.DIT and SAM also signal malicious activity.

What credential types enable lateral movement after extraction?

Plaintext passwords allow immediate reuse for interactive authentication. NT/LM hashes enable Pass-the-Hash techniques. Kerberos tickets, including TGTs, can be replayed or forged toward Golden Ticket creation when attackers harvest necessary secrets like the krbtgt account hash.

Can defenders detect Kerberos misuse or ticket-based attacks?

Yes. Indicators include unusual service ticket requests, long-lived or non-expiring TGTs, atypical account impersonation, and anomalous access to domain controllers. Correlating Kerberos events with account activity and EDR telemetry helps surface ticket misuse early.

What containment steps should be taken after detecting credential dumping?

Immediately isolate affected endpoints, reset compromised credentials (including krbtgt if suspected), revoke active sessions, and perform full forensic imaging of impacted systems. Follow an incident response playbook to preserve evidence and rebuild trust boundaries.

How effective is endpoint protection against credential extraction?

Modern EDR solutions can detect behaviors like memory scraping, LSASS handle access, and suspicious tool execution. However, legacy AV may miss in-memory-only techniques. Behavior-focused detection and blocking of suspicious process interactions are more reliable than signature-only approaches.

What hardening measures reduce credential theft risk?

Enforce multifactor authentication, restrict and rate-limit RDP, disable unnecessary interactive logons for privileged accounts, adopt Credential Guard, implement Microsoft LAPS for unique local admin passwords, and limit cached credentials. Apply least privilege and segment privilege accounts away from daily use.

Should organizations block specific open-source tools?

Blocking known tool binaries helps, but attackers rename or recompile code. Prioritize behavior-based detection: monitor for suspicious memory access, process injection, and LSASS handle duplication. Maintain threat intelligence feeds and reputation lists as a secondary control.

How do domain controllers become targets after credential theft?

Attackers use harvested credentials to authenticate to domain controllers, extract NTDS.DIT, or request privileged tokens. With domain-level secrets, they can create Golden Tickets or persist through service accounts, amplifying compromise across the environment.

What forensic signals point to attempts against NTDS.DIT and SAM?

Evidence includes volume shadow copy creation, use of utilities accessing registry hives (SYSTEM, SAM), suspicious service stoppages, abnormal file reads of NTDS.DIT, and elevated process privileges performing offline backups or replication requests.

How often should privileged credentials be rotated and audited?

Rotate high-privilege passwords and service account secrets regularly—at minimum every 90 days or sooner for critical accounts. Audit privileged access continuously, log authentication successes and failures, and require just-in-time access where possible to reduce standing credentials.

What role does MFA play against credential-based lateral movement?

Multifactor authentication significantly reduces risk from stolen passwords and replayed hashes or tickets for interactive logons. While some attack paths can bypass MFA (e.g., forged tickets used by compromised services), MFA blocks many common lateral movement techniques.

Are there safe ways to test for credential exposure internally?

Yes—perform authorized red team exercises and controlled purple team tests that follow strict rules of engagement. Use vetted tools in isolated labs or under EDR supervision to validate detections and hardening controls without risking production stability.

What should small businesses prioritize to defend against these threats?

Start with patching, enforce MFA on all remote access, limit RDP exposure, adopt unique local admin passwords through LAPS, and deploy an EDR that flags memory and LSASS access. Focus on cost-effective controls that reduce attack surface and improve visibility.

Ethan Cross

Ethan Cross is a cybersecurity analyst and tech journalist with over a decade of experience in ethical hacking, malware analysis, and digital forensics. At HakTechs.com, he delivers in-depth reports, security tips, and expert analysis to help readers stay ahead of emerging cyber threats.