
Top picks: Donut, LaZagne Project, Fridump — plus 45 more compared.
Security Operationsmimikatz is a free tool. Security professionals most commonly compare it with . All 48 alternatives are matched by shared capabilities, tags, and NIST CSF 2.0 coverage.
A closer look at the 8 most relevant alternatives and competitors to mimikatz, including their key features and shared capabilities.
A shellcode generator that creates position-independent code for loading and executing .NET Assemblies, PE files, and Windows payloads from memory.
Open source application for retrieving passwords stored on a local computer with support for various software and platforms.
Fridump is an open source memory dumping tool that uses the Frida framework to extract accessible memory addresses from iOS, Android, and Windows applications for security testing and analysis.
CLI cheatsheet for Red Specter's 30-tool offensive security platform.
A Python library for working with network protocols
GraphSpy is a browser-based post-exploitation tool for Azure Active Directory and Office 365 environments that enables token management, reconnaissance, and interaction with Microsoft 365 services.
Semi-tethered jailbreak for iPhone 5s to iPhone X, running iOS 12.0 and up, using the 'checkm8' bootrom exploit.
A collection of Python scripts for password spraying attacks against Lync/S4B & OWA, featuring Atomizer, Vaporizer, Aerosol, and Spindrift tools.
A shellcode generator that creates position-independent code for loading and executing .NET Assemblies, PE files, and Windows payloads from memory.
Open source application for retrieving passwords stored on a local computer with support for various software and platforms.
Fridump is an open source memory dumping tool that uses the Frida framework to extract accessible memory addresses from iOS, Android, and Windows applications for security testing and analysis.
CLI cheatsheet for Red Specter's 30-tool offensive security platform.
GraphSpy is a browser-based post-exploitation tool for Azure Active Directory and Office 365 environments that enables token management, reconnaissance, and interaction with Microsoft 365 services.
Semi-tethered jailbreak for iPhone 5s to iPhone X, running iOS 12.0 and up, using the 'checkm8' bootrom exploit.
A collection of Python scripts for password spraying attacks against Lync/S4B & OWA, featuring Atomizer, Vaporizer, Aerosol, and Spindrift tools.
SharpAppLocker is a C# tool that retrieves AppLocker application control policies from Windows systems, replicating the Get-AppLockerPolicy PowerShell cmdlet functionality.
Darkarmour is an open-source Windows antivirus evasion framework that enables security professionals to bypass antivirus detection through customizable obfuscation and anti-analysis techniques.
A COM Command & Control framework that uses JScript to provide fileless remote access capabilities on Windows systems through a modular plugin architecture.
PwnAuth is an open-source tool for generating and managing authentication tokens across multiple protocols, designed for penetration testing and red team exercises.
TikiTorch is a process injection tool that executes code within the address space of other processes using various injection techniques.
PowerSploit is a PowerShell-based penetration testing framework containing modules for code execution, injection techniques, persistence, and various offensive security operations.
A repository documenting AppLocker bypass techniques with verified methods, legacy DLL execution approaches, and a PowerShell module for identifying AppLocker weaknesses.
KeeFarce extracts cleartext password database information from KeePass 2.x processes in memory using DLL injection and .NET runtime manipulation.
A collection of tools that execute programs directly in memory using various delivery methods including URL downloads and netcat connections.
A tool to dump login passwords from Linux desktop users, leveraging cleartext credentials in memory.
SigThief extracts digital signatures from signed PE files and appends them to other files to create invalid signatures for testing Anti-Virus detection mechanisms.
CloudCopy implements a cloud version of the Shadow Copy attack to extract domain user hashes from AWS-hosted domain controllers by creating and mounting volume snapshots.
A command line utility for managing volume shadow copies with capabilities for evasion, persistence, and file extraction.
A tool that exposes the functionality of the Volume Shadow Copy Service (VSS) for creation, enumeration, and manipulation of volume shadow copies, with features for persistence and evasion.
A comprehensive repository of red teaming resources including cheatsheets, detailed notes, automation scripts, and practice platforms covering multiple cybersecurity domains.
Threat emulation tool for adversary simulations and red team operations
Private training course for IoT device pentesting and exploitation
DNS reconnaissance tool checking DNS records, subdomains, and third-party svcs
Whole-system emulation environment for software dev, debugging, testing & security
Automated hardware reversing platform using robotics for embedded device analysis
FourCore ATTACK is an adversary emulation platform to manage cyber risk with evidence
Post-exploitation threat emulation platform for red team operations.
Red team toolkit for EDR evasion, initial access, and post-exploitation.
Bundled offensive security suites combining pen testing, red teaming, and VM.
AI agent platform for automating offensive security operations and evals.
AI-assisted vulnerability research and advanced offensive cyber tooling firm.
Offensive security firm offering AI pentesting, credential monitoring & compliance.
R&D firm providing cyber defense & operational tech for DoD and DHS.
AI agent for in-depth binary analysis and reverse engineering assistance.
Boutique security firm offering red team, OSINT, and adversary simulation services.
MCP server enabling AI agents to autonomously run 150+ security tools
An AI-powered Google Dorking tool that helps create effective search queries to uncover sensitive information on the internet.
A specification/framework for extending default C2 communication channels in Cobalt Strike
An open-source framework that enables building and deploying AI security tools
An open source machine code decompiler that converts binary executables into readable C source code across multiple architectures and file formats.
An Android port of the Radamsa fuzzing tool compiled with Android NDK to support Android ABIs for security testing on mobile platforms.
A covert channel technique that uses WebDAV protocol features to deliver malicious payloads and establish C2 communication while bypassing security controls.
LinksDumper extracts links and endpoints from HTTP responses to support web application security testing and reconnaissance activities.
Common questions security professionals ask when evaluating alternatives and competitors to mimikatz.
The most popular alternatives to mimikatz include Donut, LaZagne Project, Fridump, Red Specter Cheatsheet, and Impacket. These Offensive Security tools offer similar capabilities and are frequently compared by security professionals evaluating their options.