Refer to the exhibit. What is the goal of the 'sekurlsa::logonpasswords' command in the Mimikatz tool, and why is it considered a 'game over' scenario for a compromised system?
Exhibit
C:\> mimikatz.exe # privilege::debug # sekurlsa::logonpasswords
Trap 1: It cracks the SAM database file offline
This command operates on memory, not the SAM database file. The SAM database is stored on disk and is only accessible with system privileges. The command specifically targets the LSASS process memory to retrieve credentials currently held by the Windows authentication subsystem.
Trap 2: It resets the local Administrator password
This command does not modify credentials; it only reads them. Resetting the Administrator password requires different commands (e.g., 'token::elevate' followed by password change utilities). Its primary utility is credential harvesting, not credential modification or administrative password resets.
Trap 3: It clears the event logs to hide the attack
Clearing logs is done using commands like 'event::clear'. Extracting credentials from memory is purely a harvesting operation. While attackers may clear logs afterwards, 'sekurlsa::logonpasswords' has no inherent log-clearing functionality; its purpose is solely to steal identity information.
- A
It cracks the SAM database file offline
Why it fails: This command operates on memory, not the SAM database file. The SAM database is stored on disk and is only accessible with system privileges. The command specifically targets the LSASS process memory to retrieve credentials currently held by the Windows authentication subsystem.
- B
It retrieves cleartext credentials from LSASS memory
The command dumps the contents of LSASS memory, which often holds cleartext passwords for logged-in users, as well as NTLM hashes and Kerberos tickets. Gaining these credentials allows an attacker to move laterally throughout the domain with the privileges of the victim.
- C
It resets the local Administrator password
Why it fails: This command does not modify credentials; it only reads them. Resetting the Administrator password requires different commands (e.g., 'token::elevate' followed by password change utilities). Its primary utility is credential harvesting, not credential modification or administrative password resets.
- D
It clears the event logs to hide the attack
Why it fails: Clearing logs is done using commands like 'event::clear'. Extracting credentials from memory is purely a harvesting operation. While attackers may clear logs afterwards, 'sekurlsa::logonpasswords' has no inherent log-clearing functionality; its purpose is solely to steal identity information.