Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupFox Kitten | Fox Kitten has used prodump to dump credentials from LSASS. |
| T1003.001 LSASS Memory |
GroupEarth Lusca | Earth Lusca has used ProcDump to obtain the hashes of credentials by dumping the memory of the LSASS process. |
| T1003.001 LSASS Memory |
GroupSilence | Silence has used the Farse6.1 utility (based on Mimikatz) to extract credentials from lsass.exe. |
| T1003.001 LSASS Memory |
GroupWizard Spider | Wizard Spider has dumped the lsass.exe memory to harvest credentials with the use of open-source tool LaZagne. |
| T1003.001 LSASS Memory |
GroupMoonstone Sleet | Moonstone Sleet retrieved credentials from LSASS memory. |
| T1003.001 LSASS Memory |
GroupVOID MANTICORE | VOID MANTICORE has dumped LSASS credentials using `comsvcs.dll` via `rundll32.exe`. |
| T1003.001 LSASS Memory |
GroupPlay | Play has used Mimikatz and the Windows Task Manager to dump LSASS process memory. |
| T1003.001 LSASS Memory |
GroupPLATINUM | PLATINUM has used keyloggers that are also capable of dumping credentials. |
| T1003.001 LSASS Memory |
GroupMagic Hound | Magic Hound has stolen domain credentials by dumping LSASS process memory using Task Manager, comsvcs.dll, and from a Microsoft Active Directory Domain Controller using Mimikatz. |
| T1003.001 LSASS Memory |
GroupThreat Group-3390 | Threat Group-3390 actors have used a modified version of Mimikatz called Wrapikatz to dump credentials. They have also dumped credentials from domain controllers. |
| T1003.001 LSASS Memory |
GroupAPT33 | APT33 has used a variety of publicly available tools like LaZagne, Mimikatz, and ProcDump to dump credentials. |
| T1003.001 LSASS Memory |
GroupFIN8 | FIN8 harvests credentials using Invoke-Mimikatz or Windows Credentials Editor (WCE). |
| T1003.001 LSASS Memory |
GroupFIN13 | FIN13 has obtained memory dumps with ProcDump to parse and extract credentials from a victim's LSASS process memory with Mimikatz. |
| T1003.002 Security Account Manager |
GroupGALLIUM | GALLIUM used |
| T1003.002 Security Account Manager |
GroupAPT41 | APT41 extracted user account data from the Security Account Managerr (SAM), making a copy of this database from the registry using the |
| T1003.002 Security Account Manager |
GroupDragonfly | Dragonfly has dropped and executed SecretsDump to dump password hashes. |
| T1003.002 Security Account Manager |
GroupmenuPass | menuPass has used a modified version of pentesting tools wmiexec.vbs and secretsdump.py to dump credentials. |
| T1003.002 Security Account Manager |
GroupKe3chang | Ke3chang has dumped credentials, including by using gsecdump. |
| T1003.002 Security Account Manager |
GroupAPT29 | APT29 has used the `reg save` command to save registry hives. |
| T1003.002 Security Account Manager |
GroupMirrorFace | MirrorFace has used vssadmin to copy registry hives including SAM. |
| T1003.002 Security Account Manager |
GroupEmber Bear | Ember Bear acquires victim credentials by extracting registry hives such as the Security Account Manager through commands such as |
| T1003.002 Security Account Manager |
GroupAgrius | Agrius dumped the SAM file on victim machines to capture credentials. |
| T1003.002 Security Account Manager |
GroupAPT5 | APT5 has copied and exfiltrated the SAM Registry hive from targeted systems. |
| T1003.002 Security Account Manager |
GroupWizard Spider | Wizard Spider has acquired credentials from the SAM/SECURITY registry hives. |
| T1003.002 Security Account Manager |
GroupDaggerfly | Daggerfly used Reg to dump the Security Account Manager (SAM) hive from victim machines for follow-on credential extraction. |
| T1003.002 Security Account Manager |
GroupThreat Group-3390 | Threat Group-3390 actors have used gsecdump to dump credentials. They have also dumped credentials from domain controllers. |
| T1003.002 Security Account Manager |
GroupFIN13 | FIN13 has extracted the SAM and SYSTEM registry hives using the `reg.exe` binary for obtaining password hashes from a compromised machine. |
| T1003.003 NTDS |
GroupVolt Typhoon | Volt Typhoon has used ntds.util to create domain controller installation media containing usernames and password hashes. |
| T1003.003 NTDS |
GroupAPT41 | APT41 used ntdsutil to obtain a copy of the victim environment |
| T1003.003 NTDS |
GroupDragonfly | Dragonfly has dropped and executed SecretsDump to dump password hashes. They also obtained ntds.dit from domain controllers. |
| T1003.003 NTDS |
GroupmenuPass | menuPass has used Ntdsutil to dump credentials. |
| T1003.003 NTDS |
GroupHAFNIUM | HAFNIUM has stolen copies of the Active Directory database (NTDS.DIT). |
| T1003.003 NTDS |
GroupFIN6 | FIN6 has used Metasploit’s PsExec NTDSGRAB module to obtain a copy of the victim's Active Directory database. |
| T1003.003 NTDS |
GroupSandworm Team | Sandworm Team has used `ntdsutil.exe` to back up the Active Directory database, likely for credential access. |
| T1003.003 NTDS |
GroupMustang Panda | Mustang Panda has used vssadmin to create a volume shadow copy and retrieve the NTDS.dit file. Mustang Panda has also used |
| T1003.003 NTDS |
GroupScattered Spider | Scattered Spider has extracted the `NTDS.dit` file by creating volume shadow copies of virtual domain controller disks. |
| T1003.003 NTDS |
GroupKe3chang | Ke3chang has used NTDSDump and other password dumping tools to gather credentials. |
| T1003.003 NTDS |
GroupChimera | Chimera has gathered the SYSTEM registry and ntds.dit files from target systems. Chimera specifically has used the NtdsAudit tool to dump the password hashes of domain users via |
| T1003.003 NTDS |
GroupMirrorFace | MirrorFace has dumped NTDS.dit through volume shadow copies. |
| T1003.003 NTDS |
GroupMedusa Group | Medusa Group has accessed the ntds.dit file to engage in credential dumping. |
| T1003.003 NTDS |
GroupAPT28 | APT28 has used the ntdsutil.exe utility to export the Active Directory database for credential access. |
| T1003.003 NTDS |
GroupFox Kitten | Fox Kitten has used Volume Shadow Copy to access credential information from NTDS. |
| T1003.003 NTDS |
GroupLAPSUS$ | LAPSUS$ has used Windows built-in tool `ntdsutil` to extract the Active Directory (AD) database. |
| T1003.003 NTDS |
GroupWizard Spider | Wizard Spider has gained access to credentials via exported copies of the ntds.dit Active Directory database. Wizard Spider has also created a volume shadow copy and used a batch script file to collect NTDS.dit with the use of the Windows utility, ntdsutil. |
| T1003.003 NTDS |
GroupFIN13 | FIN13 has harvested the NTDS.DIT file and leveraged the Impacket tool on the compromised domain controller to locally decrypt it. |
| T1003.004 LSA Secrets |
GroupDragonfly | Dragonfly has dropped and executed SecretsDump to dump password hashes. |
| T1003.004 LSA Secrets |
GroupmenuPass | menuPass has used a modified version of pentesting tools wmiexec.vbs and secretsdump.py to dump credentials. |
| T1003.004 LSA Secrets |
GroupMuddyWater | MuddyWater has performed credential dumping with LaZagne. |
| T1003.004 LSA Secrets |
GroupLeafminer | Leafminer used several tools for retrieving login and password information, including LaZagne. |
| T1003.004 LSA Secrets |
GroupOilRig | OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.