ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupFox Kitten

Fox Kitten has used prodump to dump credentials from LSASS.

T1003.001
LSASS Memory
GroupEarth Lusca

Earth Lusca has used ProcDump to obtain the hashes of credentials by dumping the memory of the LSASS process.

T1003.001
LSASS Memory
GroupSilence

Silence has used the Farse6.1 utility (based on Mimikatz) to extract credentials from lsass.exe.

T1003.001
LSASS Memory
GroupWizard Spider

Wizard Spider has dumped the lsass.exe memory to harvest credentials with the use of open-source tool LaZagne.

T1003.001
LSASS Memory
GroupMoonstone Sleet

Moonstone Sleet retrieved credentials from LSASS memory.

T1003.001
LSASS Memory
GroupVOID MANTICORE

VOID MANTICORE has dumped LSASS credentials using `comsvcs.dll` via `rundll32.exe`.

T1003.001
LSASS Memory
GroupPlay

Play has used Mimikatz and the Windows Task Manager to dump LSASS process memory.

T1003.001
LSASS Memory
GroupPLATINUM

PLATINUM has used keyloggers that are also capable of dumping credentials.

T1003.001
LSASS Memory
GroupMagic Hound

Magic Hound has stolen domain credentials by dumping LSASS process memory using Task Manager, comsvcs.dll, and from a Microsoft Active Directory Domain Controller using Mimikatz.

T1003.001
LSASS Memory
GroupThreat Group-3390

Threat Group-3390 actors have used a modified version of Mimikatz called Wrapikatz to dump credentials. They have also dumped credentials from domain controllers.

T1003.001
LSASS Memory
GroupAPT33

APT33 has used a variety of publicly available tools like LaZagne, Mimikatz, and ProcDump to dump credentials.

T1003.001
LSASS Memory
GroupFIN8

FIN8 harvests credentials using Invoke-Mimikatz or Windows Credentials Editor (WCE).

T1003.001
LSASS Memory
GroupFIN13

FIN13 has obtained memory dumps with ProcDump to parse and extract credentials from a victim's LSASS process memory with Mimikatz.

T1003.002
Security Account Manager
GroupGALLIUM

GALLIUM used reg commands to dump specific hives from the Windows Registry, such as the SAM hive, and obtain password hashes.

T1003.002
Security Account Manager
GroupAPT41

APT41 extracted user account data from the Security Account Managerr (SAM), making a copy of this database from the registry using the reg save command or by exploiting volume shadow copies.

T1003.002
Security Account Manager
GroupDragonfly

Dragonfly has dropped and executed SecretsDump to dump password hashes.

T1003.002
Security Account Manager
GroupmenuPass

menuPass has used a modified version of pentesting tools wmiexec.vbs and secretsdump.py to dump credentials.

T1003.002
Security Account Manager
GroupKe3chang

Ke3chang has dumped credentials, including by using gsecdump.

T1003.002
Security Account Manager
GroupAPT29

APT29 has used the `reg save` command to save registry hives.

T1003.002
Security Account Manager
GroupMirrorFace

MirrorFace has used vssadmin to copy registry hives including SAM.

T1003.002
Security Account Manager
GroupEmber Bear

Ember Bear acquires victim credentials by extracting registry hives such as the Security Account Manager through commands such as reg save.

T1003.002
Security Account Manager
GroupAgrius

Agrius dumped the SAM file on victim machines to capture credentials.

T1003.002
Security Account Manager
GroupAPT5

APT5 has copied and exfiltrated the SAM Registry hive from targeted systems.

T1003.002
Security Account Manager
GroupWizard Spider

Wizard Spider has acquired credentials from the SAM/SECURITY registry hives.

T1003.002
Security Account Manager
GroupDaggerfly

Daggerfly used Reg to dump the Security Account Manager (SAM) hive from victim machines for follow-on credential extraction.

T1003.002
Security Account Manager
GroupThreat Group-3390

Threat Group-3390 actors have used gsecdump to dump credentials. They have also dumped credentials from domain controllers.

T1003.002
Security Account Manager
GroupFIN13

FIN13 has extracted the SAM and SYSTEM registry hives using the `reg.exe` binary for obtaining password hashes from a compromised machine.

T1003.003
NTDS
GroupVolt Typhoon

Volt Typhoon has used ntds.util to create domain controller installation media containing usernames and password hashes.

T1003.003
NTDS
GroupAPT41

APT41 used ntdsutil to obtain a copy of the victim environment ntds.dit file.

T1003.003
NTDS
GroupDragonfly

Dragonfly has dropped and executed SecretsDump to dump password hashes. They also obtained ntds.dit from domain controllers.

T1003.003
NTDS
GroupmenuPass

menuPass has used Ntdsutil to dump credentials.

T1003.003
NTDS
GroupHAFNIUM

HAFNIUM has stolen copies of the Active Directory database (NTDS.DIT).

T1003.003
NTDS
GroupFIN6

FIN6 has used Metasploit’s PsExec NTDSGRAB module to obtain a copy of the victim's Active Directory database.

T1003.003
NTDS
GroupSandworm Team

Sandworm Team has used `ntdsutil.exe` to back up the Active Directory database, likely for credential access.

T1003.003
NTDS
GroupMustang Panda

Mustang Panda has used vssadmin to create a volume shadow copy and retrieve the NTDS.dit file. Mustang Panda has also used reg save on the SYSTEM file Registry location to help extract the NTDS.dit file.

T1003.003
NTDS
GroupScattered Spider

Scattered Spider has extracted the `NTDS.dit` file by creating volume shadow copies of virtual domain controller disks.

T1003.003
NTDS
GroupKe3chang

Ke3chang has used NTDSDump and other password dumping tools to gather credentials.

T1003.003
NTDS
GroupChimera

Chimera has gathered the SYSTEM registry and ntds.dit files from target systems. Chimera specifically has used the NtdsAudit tool to dump the password hashes of domain users via msadcs.exe "NTDS.dit" -s "SYSTEM" -p RecordedTV_pdmp.txt --users-csv RecordedTV_users.csv and used ntdsutil to copy the Active Directory database.

T1003.003
NTDS
GroupMirrorFace

MirrorFace has dumped NTDS.dit through volume shadow copies.

T1003.003
NTDS
GroupMedusa Group

Medusa Group has accessed the ntds.dit file to engage in credential dumping.

T1003.003
NTDS
GroupAPT28

APT28 has used the ntdsutil.exe utility to export the Active Directory database for credential access.

T1003.003
NTDS
GroupFox Kitten

Fox Kitten has used Volume Shadow Copy to access credential information from NTDS.

T1003.003
NTDS
GroupLAPSUS$

LAPSUS$ has used Windows built-in tool `ntdsutil` to extract the Active Directory (AD) database.

T1003.003
NTDS
GroupWizard Spider

Wizard Spider has gained access to credentials via exported copies of the ntds.dit Active Directory database. Wizard Spider has also created a volume shadow copy and used a batch script file to collect NTDS.dit with the use of the Windows utility, ntdsutil.

T1003.003
NTDS
GroupFIN13

FIN13 has harvested the NTDS.DIT file and leveraged the Impacket tool on the compromised domain controller to locally decrypt it.

T1003.004
LSA Secrets
GroupDragonfly

Dragonfly has dropped and executed SecretsDump to dump password hashes.

T1003.004
LSA Secrets
GroupmenuPass

menuPass has used a modified version of pentesting tools wmiexec.vbs and secretsdump.py to dump credentials.

T1003.004
LSA Secrets
GroupMuddyWater

MuddyWater has performed credential dumping with LaZagne.

T1003.004
LSA Secrets
GroupLeafminer

Leafminer used several tools for retrieving login and password information, including LaZagne.

T1003.004
LSA Secrets
GroupOilRig

OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.