MimiPenguin

MimiPenguin is a credential dumper, similar to Mimikatz, designed specifically for Linux platforms. [1]

ID: S0179
Type: TOOL
Platforms: Linux
Contributors: Vincent Le Toux
Version: 1.2
Created: 16 January 2018
Last Modified: 15 October 2021

Techniques Used

Domain ID Name Use
Enterprise T1003 .007 OS Credential Dumping: Proc Filesystem

MimiPenguin can use the <PID>/maps and <PID>/mem file to search for regex patterns and dump the process memory.[1][2]

Groups That Use This Software

ID Name References
G0139 TeamTNT

[3]

References