Mimipenguin

Auth/lab ref: Linux secret-exposure audit; process/memory artifact review for authorized recovery and defensive validation.

AeonDave 68edff3 1.3 KB Updated

File contents

MimiPenguin

Linux credential dumper — extract plaintext passwords from memory (Mimikatz-equivalent for Linux).

Quick Start

# Requires root
git clone https://github.com/huntergregal/mimipenguin
cd mimipenguin

# Python version
sudo python3 mimipenguin.py

# Shell version
sudo bash mimipenguin.sh

Sources Dumped

Source Notes
GNOME Keyring /proc/<PID>/mem of gnome-keyring-daemon
VSFTPd Active FTP session credentials
Apache Basic Auth HTTP Basic Auth from apache2 process
SSH SSH passphrase from ssh-agent
gdm3 GNOME Display Manager login
su Credentials from su process

Common Workflows

Quick dump all sources:

sudo python3 mimipenguin.py 2>/dev/null

Shell version (no python dependency):

sudo bash mimipenguin.sh

Redirect output:

sudo python3 mimipenguin.py | tee /tmp/.creds

Note: Effectiveness depends on what services are running and memory layout.

Resources

File When to load
references/ Process memory dump techniques on Linux

AeonDave/malskill/tree/main/offensive-tools/linux/mimipenguin commit 68edff3895

Frequently asked questions

npx skillmds@latest add aeondave/mimipenguin