[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fYWTc7RmJbsoEjS5BWV0-SbKvMUwkSdSokhAq__syT9g":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},488,"How does misc::memssp differ from SSP registration for credential extraction?","`misc::memssp` directly modifies the lsass process memory to inject code that captures credentials, rather than registering a legitimate SSP. This in-memory patching approach avoids file writes to disk and registry changes, generating a log at `mimilsa.log`. It is comparable to techniques used in [Password Filter DLL](\u002Fnews\u002Fapplication-of-password-filter-dll-in-penetration-testing) but operates purely in memory, making it harder to detect.","\u003Cp>`misc::memssp` directly modifies the lsass process memory to inject code that captures credentials, rather than registering a legitimate SSP. This in-memory patching approach avoids file writes to disk and registry changes, generating a log at `mimilsa.log`. It is comparable to techniques used in [Password Filter DLL](\u002Fnews\u002Fapplication-of-password-filter-dll-in-penetration-testing) but operates purely in memory, making it harder to detect.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fusage-of-ssp-in-mimikatz\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-does-miscmemssp-differ-from-ssp-registration-for-credential-extraction-1777483393297","memssp, memory patching, lsass, credential capture, in-memory attack",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":20,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},121,"Usage of SSP in Mimikatz","usage-of-ssp-in-mimikatz","Learn how Mimikatz SSP extracts plaintext passwords from lsass, develop custom SSPs, and bypass Windows restrictions for credential access.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Both mimilib(ssp) in Mimikatz and misc::memssp share the same functionality as sekurlsa::wdigest, capable of extracting credentials from the lsass process, typically obtaining plaintext passwords of logged-in users (by default, this is not possible on Windows Server 2008 R2 and later systems). However, their implementation principles differ, so the methods to bypass restrictions on newer versions also vary.\u003C\u002Fp>\u003Cp>I studied XPN's second article and gained new insights into this technique, so I attempted to summarize it and add some personal understanding.\u003C\u002Fp>\u003Cp>XPN's blog:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblog.xpnsec.com\u002Fexploring-mimikatz-part-2\u002F\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to SSP\u003C\u002Fli>\u003Cli>How to Develop an SSP\u003C\u002Fli>\u003Cli>How to Enumerate and Remove SSP\u003C\u002Fli>\u003Cli>Three Methods to Add SSP\u003C\u002Fli>\u003Cli>The Method of Modifying Memory with memssp\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to SSP\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fprevious-versions\u002Fwindows\u002Fit-pro\u002Fwindows-server-2012-R2-and-2012\u002Fdn751052(v=ws.11)\u003C\u002Fp>\u003Cp>SSP, full name Security Support Provider, also known as Security Package\u003C\u002Fp>\u003Cp>SSPI, full name Security Support Provider Interface, is the API used by Windows systems for authentication operations\u003C\u002Fp>\u003Cp>Simply understood, SSPI is the API interface for SSP\u003C\u002Fp>\u003Cp>SSP includes the following by default:\u003C\u002Fp>\u003Cul>\u003Cli>Kerberos Security Support Provider\u003C\u002Fli>\u003Cli>NTLM Security Support Provider\u003C\u002Fli>\u003Cli>Digest Security Support Provider\u003C\u002Fli>\u003Cli>Schannel Security Support Provider\u003C\u002Fli>\u003Cli>Negotiate Security Support Provider\u003C\u002Fli>\u003Cli>Credential Security Support Provider\u003C\u002Fli>\u003Cli>Negotiate Extensions Security Support Provider\u003C\u002Fli>\u003Cli>PKU2U Security Support Provider\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Users can develop and add SSPs themselves, which can operate on certain authentication and authorization events in the system.\u003C\u002Fp>\u003Cp>This article only covers how to add an SSP to extract plaintext credentials from the lsass process.\u003C\u002Fp>\u003Ch2>0x03 How to Develop an SSP\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>An SSP is a DLL, with different functions corresponding to different export functions.\u003C\u002Fp>\u003Cp>mimilib in mimikatz can not only serve as an SSP but also includes other functionalities.\u003C\u002Fp>\u003Cp>The export function that implements credential extraction from the lsass process is SpLsaModeInitialize.\u003C\u002Fp>\u003Cp>To extract this functionality, other export functions can be removed. The modified mimilib.def content is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>LIBRARY\u003Cbr>EXPORTS\u003Cbr>SpLsaModeInitialize\t\t=\tkssp_SpLsaModeInitialize\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Implementation code for mimilib extracting plaintext credentials from the lsass process:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgentilkiwi\u002Fmimikatz\u002Fblob\u002Fmaster\u002Fmimilib\u002Fkssp.c\u003C\u002Fp>\u003Cp>The implementation code includes the following four functions:\u003C\u002Fp>\u003Col>\u003Cli>SpInitialize\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Used to initialize SSP and provide a list of function pointers\u003C\u002Fp>\u003Col>\u003Cli>SpShutDown\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Called to unload SSP\u003C\u002Fp>\u003Col>\u003Cli>SpGetInfo\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Provides information about SSP, including version, name, and description\u003C\u002Fp>\u003Cp>These details are displayed when enumerating SSP (the method will be introduced later)\u003C\u002Fp>\u003Col>\u003Cli>SpAcceptCredentials\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Receives plaintext credentials passed by LSA, cached by SSP\u003C\u002Fp>\u003Cp>mimilib here implements saving plaintext credentials to the file c:\\windows\\system32\\kiwissp.log\u003C\u002Fp>\u003Ch2>0x04 How to Enumerate and Remove SSP\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Enumerate SSP\u003C\u002Fh3>\u003Cp>Test code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#define SECURITY_WIN32\u003Cbr>\u003Cbr>#include \u003Cstdio.h>\u003Cbr>#include \u003Cwindows.h>\u003Cbr>#include \u003Csecurity.h>\u003Cbr>#pragma comment(lib,\"Secur32.lib\")\u003Cbr>\u003Cbr>int main(int argc, char **argv) {\u003Cbr>\tULONG packageCount = 0;\u003Cbr>\tPSecPkgInfoA packages;\u003Cbr>\u003Cbr>\tif (EnumerateSecurityPackagesA(&amp;packageCount, &amp;packages) == SEC_E_OK) {\u003Cbr>\t\tfor (int i = 0; i &lt; packageCount; i++) {\u003Cbr>\t\t\tprintf(\"Name: %s\\nComment: %s\\n\\n\", packages[i].Name, packages[i].Comment);\u003Cbr>\t\t}\u003Cbr>\t}\u003Cbr>}\u003C\u002Fsecurity.h>\u003C\u002Fwindows.h>\u003C\u002Fstdio.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Code excerpt from XPN's article\u003C\u002Fp>\u003Cp>The default result is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017949263_0_e17188a96d.jpeg\">\u003C\u002Fp>\u003Ch3>2. Delete SSP\u003C\u002Fh3>\u003Cp>Test code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#define SECURITY_WIN32\u003Cbr>\u003Cbr>#include \u003Cstdio.h>\u003Cbr>#include \u003Cwindows.h>\u003Cbr>#include \u003Csecurity.h>\u003Cbr>#pragma comment(lib,\"Secur32.lib\")\u003Cbr>\u003Cbr>\u003Cbr>int main(int argc, char **argv) {\u003Cbr>\u003Cbr>\tSECURITY_STATUS SEC_ENTRYnRet = DeleteSecurityPackageA(argv[1]);\u003Cbr>\tprintf(\"DeleteSecurityPackageA return with 0x%X\\n\", SEC_ENTRYnRet);\u003Cbr>\u003Cbr>}\u003C\u002Fsecurity.h>\u003C\u002Fwindows.h>\u003C\u002Fstdio.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After testing, it is not possible to delete any SSP; it always reports an error, indicating 0x80090302\u003C\u002Fp>\u003Cp>After searching, an article with the same result was found:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fcybernigma.blogspot.com\u002F2014\u002F03\u002Fusing-sspap-lsass-proxy-to-mitigate.html\u003C\u002Fp>\u003Cp>It is speculated that Microsoft has not opened this feature, meaning SSP cannot be deleted without restarting the system.\u003C\u002Fp>\u003Cp>\u003Cstrong>Supplement:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>To unload a DLL from a process, the following code can be used:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch2>0x05 Three Methods to Add SSP\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Here, using mimilib.dll as an example\u003C\u002Fp>\u003Ch3>Method 1:\u003C\u002Fh3>\u003Cp>(1) Copy the file\u003C\u002Fp>\u003Cp>Copy mimilib.dll to c:\\windows\\system32\u003C\u002Fp>\u003Cp>For 64-bit systems, use the 64-bit mimilib.dll; for 32-bit systems, use the 32-bit mimilib.dll.\u003C\u002Fp>\u003Cp>(2) Modify the registry\u003C\u002Fp>\u003Cp>Navigate to HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Lsa\\\u003C\u002Fp>\u003Cp>Set the value of Security Packages to mimilib.dll\u003C\u002Fp>\u003Cp>(3) Wait for the system to restart\u003C\u002Fp>\u003Cp>After the system restarts, generate the file kiwissp.log in c:\\windows\\system32, recording the plaintext password of the current user\u003C\u002Fp>\u003Ch3>Method 2: Using the API AddSecurityPackage\u003C\u002Fh3>\u003Cp>(1) Copy files\u003C\u002Fp>\u003Cp>Same as Method 1\u003C\u002Fp>\u003Cp>(2) Modify the registry\u003C\u002Fp>\u003Cp>Same as Method 1\u003C\u002Fp>\u003Cp>(3) Call AddSecurityPackage\u003C\u002Fp>\u003Cp>Test code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#define SECURITY_WIN32\u003Cbr>\u003Cbr>#include \u003Cstdio.h>\u003Cbr>#include \u003Cwindows.h>\u003Cbr>#include \u003Csecurity.h>\u003Cbr>#pragma comment(lib,\"Secur32.lib\")\u003Cbr>\u003Cbr>\u003Cbr>int main(int argc, char **argv) {\u003Cbr>\tSECURITY_PACKAGE_OPTIONS option;\u003Cbr>\toption.Size = sizeof(option);\u003Cbr>\toption.Flags = 0;\u003Cbr>\toption.Type = SECPKG_OPTIONS_TYPE_LSA;\u003Cbr>\toption.SignatureSize = 0;\u003Cbr>\toption.Signature = NULL;\u003Cbr>\tSECURITY_STATUS SEC_ENTRYnRet = AddSecurityPackageA(\"mimilib\", &amp;option);\u003Cbr>\tprintf(\"AddSecurityPackage return with 0x%X\\n\", SEC_ENTRYnRet);\u003Cbr>}\u003C\u002Fsecurity.h>\u003C\u002Fwindows.h>\u003C\u002Fstdio.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>If successful, entering new credentials (e.g., runas, or after a user locks and re-logs into the screen) will generate the file kiwissp.log\u003C\u002Fp>\u003Cp>Automated implementation of Method 2:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FEmpireProject\u002FEmpire\u002Fblob\u002Fe37fb2eef8ff8f5a0a689f1589f424906fe13055\u002Fdata\u002Fmodule_source\u002Fpersistence\u002FInstall-SSP.ps1\u003C\u002Fp>\u003Ch3>Method 3: Using RPC to control lsass to load SSP\u003C\u002Fh3>\u003Cp>Open-source code by XPN:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002Fxpn\u002Fc7f6d15bf15750eae3ec349e7ec2380e\u003C\u002Fp>\u003Cp>I am using it under VS2015, the code needs to be slightly modified.\u003C\u002Fp>\u003Cp>Test as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017956180_1_caff8d0222.jpeg\">\u003C\u002Fp>\u003Cp>Added successfully.\u003C\u002Fp>\u003Cp>Note:\u003C\u002Fp>\u003Cp>If the XPN open-source code is compiled to use MFC in a static library, the following code needs to be added: #pragma comment(lib, \"Rpcrt4.lib\")\u003C\u002Fp>\u003Cp>If the XPN open-source code is not modified further, the called DLL needs to use an absolute path (the code in my screenshot has been modified, so it supports relative paths).\u003C\u002Fp>\u003Cp>Returning Error code 0x6c6 returned, which is expected if DLL load returns FALSE indicates that the DLL loaded successfully.\u003C\u002Fp>\u003Cp>This is an excellent method with the following advantages:\u003C\u002Fp>\u003Cul>\u003Cli>No need to write to the registry.\u003C\u002Fli>\u003Cli>Does not call the API AddSecurityPackage.\u003C\u002Fli>\u003Cli>No write operations to the memory of the lsass process are required.\u003C\u002Fli>\u003Cli>The loaded DLL does not exist in the lsass process.\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x06 memssp method for modifying memory.\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This is a feature in mimikatz, with the command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>misc::memssp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>By modifying the memory of the lsass process, credentials are extracted from the lsass process\u003C\u002Fp>\u003Cp>After executing the command, if new credentials are entered (e.g., runas, or after a user locks the screen and logs back in), a file mimilsa.log will be generated in c:\\windows\\system32\u003C\u002Fp>\u003Cp>XPN implemented the same functionality in the form of a DLL using mimikatz's code as a template, which can be loaded via RPC (method 3 in 0x05) or LoadLibrary\u003C\u002Fp>\u003Cp>Code repository:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002Fxpn\u002F93f2b75bf086baf2c388b2ddd50fb5d0\u003C\u002Fp>\u003Cp>The code is applicable to WIN_BUILD_10_1703x64 and WIN_BUILD_10_1809x64\u003C\u002Fp>\u003Cp>For other systems, corresponding variables need to be modified. Refer to the location:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgentilkiwi\u002Fmimikatz\u002Fblob\u002F72b83acb297f50758b0ce1de33f722e70f476250\u002Fmimikatz\u002Fmodules\u002Fkuhl_m_misc.c#L483\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article combines XPN's post to introduce methods for extracting credentials from the lsass process using Mimikatz's mimilib(ssp) and misc::memssp, compiling related techniques including development, addition, enumeration of SSP, and memory patching\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Both mimilib(ssp) in Mimikatz and misc::memssp share the same functionality as sekurlsa::wdigest, capable of extracting credentials from the lsass process, typically obtaining plaintext passwords of logged-in users (by default, this is not possible on Windows Server 2008 R2 and later systems). However, their implementation principles differ, so the methods to bypass restrictions on newer versions also vary.\u003C\u002Fp>\u003Cp>I studied XPN's second article and gained new insights into this technique, so I attempted to summarize it and add some personal understanding.\u003C\u002Fp>\u003Cp>XPN's blog:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblog.xpnsec.com\u002Fexploring-mimikatz-part-2\u002F\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to SSP\u003C\u002Fli>\u003Cli>How to Develop an SSP\u003C\u002Fli>\u003Cli>How to Enumerate and Remove SSP\u003C\u002Fli>\u003Cli>Three Methods to Add SSP\u003C\u002Fli>\u003Cli>The Method of Modifying Memory with memssp\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to SSP\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fprevious-versions\u002Fwindows\u002Fit-pro\u002Fwindows-server-2012-R2-and-2012\u002Fdn751052(v=ws.11)\u003C\u002Fp>\u003Cp>SSP, full name Security Support Provider, also known as Security Package\u003C\u002Fp>\u003Cp>SSPI, full name Security Support Provider Interface, is the API used by Windows systems for authentication operations\u003C\u002Fp>\u003Cp>Simply understood, SSPI is the API interface for SSP\u003C\u002Fp>\u003Cp>SSP includes the following by default:\u003C\u002Fp>\u003Cul>\u003Cli>Kerberos Security Support Provider\u003C\u002Fli>\u003Cli>NTLM Security Support Provider\u003C\u002Fli>\u003Cli>Digest Security Support Provider\u003C\u002Fli>\u003Cli>Schannel Security Support Provider\u003C\u002Fli>\u003Cli>Negotiate Security Support Provider\u003C\u002Fli>\u003Cli>Credential Security Support Provider\u003C\u002Fli>\u003Cli>Negotiate Extensions Security Support Provider\u003C\u002Fli>\u003Cli>PKU2U Security Support Provider\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Users can develop and add SSPs themselves, which can operate on certain authentication and authorization events in the system.\u003C\u002Fp>\u003Cp>This article only covers how to add an SSP to extract plaintext credentials from the lsass process.\u003C\u002Fp>\u003Ch2>0x03 How to Develop an SSP\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>An SSP is a DLL, with different functions corresponding to different export functions.\u003C\u002Fp>\u003Cp>mimilib in mimikatz can not only serve as an SSP but also includes other functionalities.\u003C\u002Fp>\u003Cp>The export function that implements credential extraction from the lsass process is SpLsaModeInitialize.\u003C\u002Fp>\u003Cp>To extract this functionality, other export functions can be removed. The modified mimilib.def content is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>LIBRARY\u003Cbr>EXPORTS\u003Cbr>SpLsaModeInitialize\t\t=\tkssp_SpLsaModeInitialize\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Implementation code for mimilib extracting plaintext credentials from the lsass process:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgentilkiwi\u002Fmimikatz\u002Fblob\u002Fmaster\u002Fmimilib\u002Fkssp.c\u003C\u002Fp>\u003Cp>The implementation code includes the following four functions:\u003C\u002Fp>\u003Col>\u003Cli>SpInitialize\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Used to initialize SSP and provide a list of function pointers\u003C\u002Fp>\u003Col>\u003Cli>SpShutDown\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Called to unload SSP\u003C\u002Fp>\u003Col>\u003Cli>SpGetInfo\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Provides information about SSP, including version, name, and description\u003C\u002Fp>\u003Cp>These details are displayed when enumerating SSP (the method will be introduced later)\u003C\u002Fp>\u003Col>\u003Cli>SpAcceptCredentials\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Receives plaintext credentials passed by LSA, cached by SSP\u003C\u002Fp>\u003Cp>mimilib here implements saving plaintext credentials to the file c:\\windows\\system32\\kiwissp.log\u003C\u002Fp>\u003Ch2>0x04 How to Enumerate and Remove SSP\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Enumerate SSP\u003C\u002Fh3>\u003Cp>Test code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#define SECURITY_WIN32\u003Cbr>\u003Cbr>#include \u003Cstdio.h>\u003Cbr>#include \u003Cwindows.h>\u003Cbr>#include \u003Csecurity.h>\u003Cbr>#pragma comment(lib,\"Secur32.lib\")\u003Cbr>\u003Cbr>int main(int argc, char **argv) {\u003Cbr>\tULONG packageCount = 0;\u003Cbr>\tPSecPkgInfoA packages;\u003Cbr>\u003Cbr>\tif (EnumerateSecurityPackagesA(&amp;packageCount, &amp;packages) == SEC_E_OK) {\u003Cbr>\t\tfor (int i = 0; i &lt; packageCount; i++) {\u003Cbr>\t\t\tprintf(\"Name: %s\\nComment: %s\\n\\n\", packages[i].Name, packages[i].Comment);\u003Cbr>\t\t}\u003Cbr>\t}\u003Cbr>}\u003C\u002Fsecurity.h>\u003C\u002Fwindows.h>\u003C\u002Fstdio.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Code excerpt from XPN's article\u003C\u002Fp>\u003Cp>The default result is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017949263_0_e17188a96d-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Delete SSP\u003C\u002Fh3>\u003Cp>Test code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#define SECURITY_WIN32\u003Cbr>\u003Cbr>#include \u003Cstdio.h>\u003Cbr>#include \u003Cwindows.h>\u003Cbr>#include \u003Csecurity.h>\u003Cbr>#pragma comment(lib,\"Secur32.lib\")\u003Cbr>\u003Cbr>\u003Cbr>int main(int argc, char **argv) {\u003Cbr>\u003Cbr>\tSECURITY_STATUS SEC_ENTRYnRet = DeleteSecurityPackageA(argv[1]);\u003Cbr>\tprintf(\"DeleteSecurityPackageA return with 0x%X\\n\", SEC_ENTRYnRet);\u003Cbr>\u003Cbr>}\u003C\u002Fsecurity.h>\u003C\u002Fwindows.h>\u003C\u002Fstdio.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After testing, it is not possible to delete any SSP; it always reports an error, indicating 0x80090302\u003C\u002Fp>\u003Cp>After searching, an article with the same result was found:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fcybernigma.blogspot.com\u002F2014\u002F03\u002Fusing-sspap-lsass-proxy-to-mitigate.html\u003C\u002Fp>\u003Cp>It is speculated that Microsoft has not opened this feature, meaning SSP cannot be deleted without restarting the system.\u003C\u002Fp>\u003Cp>\u003Cstrong>Supplement:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>To unload a DLL from a process, the following code can be used:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch2>0x05 Three Methods to Add SSP\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Here, using mimilib.dll as an example\u003C\u002Fp>\u003Ch3>Method 1:\u003C\u002Fh3>\u003Cp>(1) Copy the file\u003C\u002Fp>\u003Cp>Copy mimilib.dll to c:\\windows\\system32\u003C\u002Fp>\u003Cp>For 64-bit systems, use the 64-bit mimilib.dll; for 32-bit systems, use the 32-bit mimilib.dll.\u003C\u002Fp>\u003Cp>(2) Modify the registry\u003C\u002Fp>\u003Cp>Navigate to HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Lsa\\\u003C\u002Fp>\u003Cp>Set the value of Security Packages to mimilib.dll\u003C\u002Fp>\u003Cp>(3) Wait for the system to restart\u003C\u002Fp>\u003Cp>After the system restarts, generate the file kiwissp.log in c:\\windows\\system32, recording the plaintext password of the current user\u003C\u002Fp>\u003Ch3>Method 2: Using the API AddSecurityPackage\u003C\u002Fh3>\u003Cp>(1) Copy files\u003C\u002Fp>\u003Cp>Same as Method 1\u003C\u002Fp>\u003Cp>(2) Modify the registry\u003C\u002Fp>\u003Cp>Same as Method 1\u003C\u002Fp>\u003Cp>(3) Call AddSecurityPackage\u003C\u002Fp>\u003Cp>Test code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#define SECURITY_WIN32\u003Cbr>\u003Cbr>#include \u003Cstdio.h>\u003Cbr>#include \u003Cwindows.h>\u003Cbr>#include \u003Csecurity.h>\u003Cbr>#pragma comment(lib,\"Secur32.lib\")\u003Cbr>\u003Cbr>\u003Cbr>int main(int argc, char **argv) {\u003Cbr>\tSECURITY_PACKAGE_OPTIONS option;\u003Cbr>\toption.Size = sizeof(option);\u003Cbr>\toption.Flags = 0;\u003Cbr>\toption.Type = SECPKG_OPTIONS_TYPE_LSA;\u003Cbr>\toption.SignatureSize = 0;\u003Cbr>\toption.Signature = NULL;\u003Cbr>\tSECURITY_STATUS SEC_ENTRYnRet = AddSecurityPackageA(\"mimilib\", &amp;option);\u003Cbr>\tprintf(\"AddSecurityPackage return with 0x%X\\n\", SEC_ENTRYnRet);\u003Cbr>}\u003C\u002Fsecurity.h>\u003C\u002Fwindows.h>\u003C\u002Fstdio.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>If successful, entering new credentials (e.g., runas, or after a user locks and re-logs into the screen) will generate the file kiwissp.log\u003C\u002Fp>\u003Cp>Automated implementation of Method 2:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FEmpireProject\u002FEmpire\u002Fblob\u002Fe37fb2eef8ff8f5a0a689f1589f424906fe13055\u002Fdata\u002Fmodule_source\u002Fpersistence\u002FInstall-SSP.ps1\u003C\u002Fp>\u003Ch3>Method 3: Using RPC to control lsass to load SSP\u003C\u002Fh3>\u003Cp>Open-source code by XPN:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002Fxpn\u002Fc7f6d15bf15750eae3ec349e7ec2380e\u003C\u002Fp>\u003Cp>I am using it under VS2015, the code needs to be slightly modified.\u003C\u002Fp>\u003Cp>Test as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017956180_1_caff8d0222-1.jpeg\">\u003C\u002Fp>\u003Cp>Added successfully.\u003C\u002Fp>\u003Cp>Note:\u003C\u002Fp>\u003Cp>If the XPN open-source code is compiled to use MFC in a static library, the following code needs to be added: #pragma comment(lib, \"Rpcrt4.lib\")\u003C\u002Fp>\u003Cp>If the XPN open-source code is not modified further, the called DLL needs to use an absolute path (the code in my screenshot has been modified, so it supports relative paths).\u003C\u002Fp>\u003Cp>Returning Error code 0x6c6 returned, which is expected if DLL load returns FALSE indicates that the DLL loaded successfully.\u003C\u002Fp>\u003Cp>This is an excellent method with the following advantages:\u003C\u002Fp>\u003Cul>\u003Cli>No need to write to the registry.\u003C\u002Fli>\u003Cli>Does not call the API AddSecurityPackage.\u003C\u002Fli>\u003Cli>No write operations to the memory of the lsass process are required.\u003C\u002Fli>\u003Cli>The loaded DLL does not exist in the lsass process.\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x06 memssp method for modifying memory.\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This is a feature in mimikatz, with the command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>misc::memssp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>By modifying the memory of the lsass process, credentials are extracted from the lsass process\u003C\u002Fp>\u003Cp>After executing the command, if new credentials are entered (e.g., runas, or after a user locks the screen and logs back in), a file mimilsa.log will be generated in c:\\windows\\system32\u003C\u002Fp>\u003Cp>XPN implemented the same functionality in the form of a DLL using mimikatz's code as a template, which can be loaded via RPC (method 3 in 0x05) or LoadLibrary\u003C\u002Fp>\u003Cp>Code repository:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002Fxpn\u002F93f2b75bf086baf2c388b2ddd50fb5d0\u003C\u002Fp>\u003Cp>The code is applicable to WIN_BUILD_10_1703x64 and WIN_BUILD_10_1809x64\u003C\u002Fp>\u003Cp>For other systems, corresponding variables need to be modified. Refer to the location:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgentilkiwi\u002Fmimikatz\u002Fblob\u002F72b83acb297f50758b0ce1de33f722e70f476250\u002Fmimikatz\u002Fmodules\u002Fkuhl_m_misc.c#L483\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article combines XPN's post to introduce methods for extracting credentials from the lsass process using Mimikatz's mimilib(ssp) and misc::memssp, compiling related techniques including development, addition, enumeration of SSP, and memory patching\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1108,"Onedaysec",5,"published","2026-02-02T07:51:00.065Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Mimikatz SSP Guide: Extract Plaintext Passwords & Bypass Restrictions","Mimikatz SSP, plaintext passwords, lsass process, security support provider, credential extraction, Windows authentication, mimilib, memssp, bypass restrictions, SSP development",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46],489,487,486,{"title":39,"description":39,"image":39},"2026-07-24T15:37:13.095Z","2026-07-23T16:01:38.504Z","draft","2026-07-23T16:12:41.169Z"]