Credential Dumping Explained: Mimikatz, LSASS and Defences for CySA+
Mimikatz is the tool that made credential dumping a mainstream concern. Its author released it to demonstrate weaknesses in how Windows handled credentials in memory, and it is now a standard component of both red team toolkits and real intrusions. This article covers what the technique is, why it works, and — the part the exams actually test — how to detect and prevent it. It is not a usage guide. Why credentials sit in memory at all Single sign-on is the reason. So that you are not prompted for a password every time you reach a file share, Windows keeps credential material available in the memory of the Local Security Authority Subsystem Service — LSASS . Historically that included reversibly encrypted plaintext passwords, because the WDigest authentication protocol required them. Anyone able to read LSASS memory with sufficient privilege could recover them. The design trade-off is the point to carry into the exam: convenience of single sign-on against the risk of credential mat...