Mimikaz captures the windows plaintext password under waf, mimikazwaf
When we get the target server, we generally use the mimkaz artifact to capture the plaintext password of the target server. However, if the target server is configured with waf, mimikaz cannot capture it, this allows you to download the dmp file containing the account and password to a local machine and use mimikaz to capture it.
Build the same system environment as the target machine. Use the following command to download the dmp file;
Procdump.exe-accepteula-ma lsass.exe % COMPUTERNAME % _ lsass. dmp
This procdump.exe is a tool in the Microsoft toolkit and will not be banned from virus ban. After the dmp is downloaded, use the two mimikaz commands to capture the windows plaintext password.
Mimikatz # sekurlsa: minidump lsass. DMPmimikatz # sekurlsa: logonPasswords full