Start with Identity
Identity Security Researcher

Benjamin Delpy

Creator of mimikatz · Independent · 15+ years in identity
Focus areas
Windows CredentialsKerberosActive DirectoryOffensive Research
Notable work
  • Created mimikatz in 2011, demonstrating how Windows stored credentials in memory
  • Documented Kerberos ticket attacks including golden and silver tickets
  • Maintains the tool against each generation of Windows credential defenses

Bio

Benjamin Delpy, who publishes as gentilkiwi, wrote mimikatz in 2011 after finding that Windows held both an encrypted copy of a password and the key to decrypt it in memory at the same time. Microsoft's initial response was that exploiting it required an already-compromised machine. He published the tool, and the industry's understanding of credential theft changed.

Profile built from public project, vendor, and press records. Included as a researcher whose published work reshaped defensive practice; this is not an endorsement of any use of the tool.

Where their work shows up

Almost every defensive control now considered standard in a Windows environment exists because mimikatz made the attack undeniable: Credential Guard, LSA protection, tiered administration, disabling WDigest, and the whole practice of treating a domain controller as a crown jewel. It also made Kerberoasting, pass-the-hash style credential reuse, and Kerberos delegation abuse teachable rather than theoretical. See the ITDR guide and the best ITDR for Active Directory ranking.

Built from public information only. This is an independent profile and is not an endorsement by, or affiliation with, the person listed. Corrections: [email protected].