{
	"id": "7f7daf20-090e-442d-b1b1-4fc319af37b1",
	"created_at": "2026-04-06T01:32:39.95929Z",
	"updated_at": "2026-04-10T03:21:14.437396Z",
	"deleted_at": null,
	"sha1_hash": "2bcee4ff663e9b74c81ab0a5c2f35ea5635c31c2",
	"title": "GitHub - GhostPack/SafetyKatz: SafetyKatz is a combination of slightly modified version of @gentilkiwi's Mimikatz project and @subtee's .NET PE Loader",
	"llm_title": "",
	"authors": "",
	"file_creation_date": "0001-01-01T00:00:00Z",
	"file_modification_date": "0001-01-01T00:00:00Z",
	"file_size": 49035,
	"plain_text": "GitHub - GhostPack/SafetyKatz: SafetyKatz is a combination of\r\nslightly modified version of @gentilkiwi's Mimikatz project and\r\n@subtee's .NET PE Loader\r\nBy HarmJ0y\r\nArchived: 2026-04-06 00:22:09 UTC\r\nSafetyKatz is a combination of slightly modified version of @gentilkiwi's Mimikatz project and @subtee's .NET\r\nPE Loader.\r\nFirst, the MiniDumpWriteDump Win32 API call is used to create a minidump of LSASS to\r\nC:\\Windows\\Temp\\debug.bin. Then @subtee's PELoader is used to load a customized version of Mimikatz that\r\nruns sekurlsa::logonpasswords and sekurlsa::ekeys on the minidump file, removing the file after execution is\r\ncomplete.\r\nModifications\r\n@subtee's PE Loader was slightly modified so some of the pointer arithmetic worked better on .NET 3.5\r\n@gentilkiwi's Mimikatz project was modified to strip some functionality for size reasons, and to\r\nautomatically run the sekurlsa::minidump mode (deleting the minidump file after). If you don't trust my\r\ncompiled version, feel free to build it yourself :)\r\n@harmj0y is the primary author of this port.\r\nSafetyKatz is licensed under the BSD 3-Clause license.\r\nUsage\r\nC:\\Temp\u003eSafetyKatz.exe\r\n[*] Dumping lsass (808) to C:\\WINDOWS\\Temp\\debug.bin\r\n[+] Dump successful!\r\n[*] Executing loaded Mimikatz PE\r\n.#####. mimikatz 2.1.1 (x64) built on Jul 7 2018 03:36:26 - lil!\r\n.## ^ ##. \"A La Vie, A L'Amour\" - (oe.eo)\r\n## / \\ ## / *** Benjamin DELPY `gentilkiwi` ( benjamin@gentilkiwi.com )\r\n## \\ / ## \u003e http://blog.gentilkiwi.com/mimikatz\r\n'## v ##' Vincent LE TOUX ( vincent.letoux@gmail.com )\r\n'#####' \u003e http://pingcastle.com / http://mysmartlogon.com *** /\r\nhttps://github.com/GhostPack/SafetyKatz\r\nPage 1 of 2\n\nmimikatz # Opening : 'C:\\Windows\\Temp\\debug.bin' file for minidump...\r\nAuthentication Id : 0 ; 28935082 (00000000:01b983aa)\r\nSession : Interactive from 0\r\nUser Name : blahuser\r\nDomain : WINDOWS10\r\nLogon Server : WINDOWS10\r\nLogon Time : 7/15/2018 1:07:55 PM\r\nSID : S-1-5-21-1473254003-2681465353-4059813368-1002\r\n msv :\r\n [00000003]\r\nPrimary\r\n * Username : blahuser\r\n * Domain : WINDOWS10\r\n...(snip)...\r\nmimikatz # deleting C:\\Windows\\Temp\\debug.bin\r\nCompile Instructions\r\nWe are not planning on releasing binaries for SafetyKatz, so you will have to compile yourself :)\r\nSafetyKatz has been built against.NET 3.5 and is compatible withVisual Studio 2015 Community Edition. Simply\r\nopen up the project .sln, choose \"release\", and build.\r\nSource: https://github.com/GhostPack/SafetyKatz\r\nhttps://github.com/GhostPack/SafetyKatz\r\nPage 2 of 2",
	"extraction_quality": 1,
	"language": "EN",
	"sources": [
		"ETDA"
	],
	"references": [
		"https://github.com/GhostPack/SafetyKatz"
	],
	"report_names": [
		"SafetyKatz"
	],
	"threat_actors": [],
	"ts_created_at": 1775439159,
	"ts_updated_at": 1775791274,
	"ts_creation_date": 0,
	"ts_modification_date": 0,
	"files": {
		"pdf": "https://archive.orkl.eu/2bcee4ff663e9b74c81ab0a5c2f35ea5635c31c2.pdf",
		"text": "https://archive.orkl.eu/2bcee4ff663e9b74c81ab0a5c2f35ea5635c31c2.txt",
		"img": "https://archive.orkl.eu/2bcee4ff663e9b74c81ab0a5c2f35ea5635c31c2.jpg"
	}
}