Which of the following offensive tools can be used by penetration testers post-exploitation or successful compromise of a user account in a network that dumps passwords from memory and hashes, PINs, and Kerberos tickets, and thus are used for privilege escalation attacks?
A. Mimikatz and hashcat
B. Powershell and procdump
C. Tor and NMAP
D. Ophcrack and John-the-Ripper
The Correct Answer is A. Mimikatz and hashcat.
Mimikatz is an open-source application that permits users to view and save authentication credentials like Kerberos tickets. Benjamin Delpy proceeds to lead Mimikatz improvements, so the toolset works with the current release of Windows and incorporates the most up-to-date attacks. Hashcat is a password recovery tool. It had a exclusive code base until 2015, but was then released as open source software. Versions are accessible for Linux, OS X, and Windows.