Windows authentication is pluggable: Security Support Providers (SSPs) are DLLs loaded into LSASS that handle authentication exchanges. Registering a malicious SSP makes LSASS hand the authentications that happen on that host, interactive and service logons, to your code, which records the cleartext password supplied during them. It does not reveal the password behind every domain authentication: a user signing in from another machine gives the DC only a Kerberos pre-authentication blob or an NTLM response, not their cleartext. What it does catch on a DC is the accounts that actually log on there, interactive admin sessions and the service and machine accounts starting locally, in cleartext.
Installing it#
Two common forms, both needing admin/SYSTEM on the target:
# Persistent: drop mimilib.dll and register it as a Security Package (survives reboot)
# copy mimilib.dll to C:\Windows\System32\
# add "mimilib" to HKLM\System\CurrentControlSet\Control\Lsa\Security Packages (REG_MULTI_SZ)
# In-memory: patch LSASS to add a logging SSP without touching disk (not reboot-persistent)
mimikatz: privilege::debug ; misc::memssp
Captured credentials are written in cleartext to a local log:
# mimilib.dll (registered SSP) logs to:
C:\Windows\System32\kiwissp.log
# misc::memssp (in-memory) logs to:
C:\Windows\System32\mimilsa.log
Why it is valuable#
- It yields plaintext passwords, not hashes, so no cracking is needed, and it catches credentials that are never in a dumpable hash form at rest.
- On a DC it still catches the service and machine accounts that log on locally, and any interactive admin logon, in cleartext, which is high value even though it is not every domain authentication.
- The registry (
Security Packages) form reloads on reboot, making it durable; thememsspform is stealthier (no disk artifact) but clears on reboot.
Exploitation notes#
- Requires LSA Protection (RunAsPPL) to be off or bypassed, since the SSP loads into LSASS; a signed/PPL-enforced LSASS blocks an unsigned package.
- It is a harvesting backdoor, not instant access: value accrues as logons happen, so leave it and collect.
- Reading
kiwissp.logneeds local access to the host, so pair it with a re-entry method (DSRM, a golden ticket).
Tools#
- Mimikatz (
misc::memssp, and themimilib.dllSSP): in-memory and on-disk logging SSPs.