Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupKimsuky | Kimsuky has gathered credentials using Mimikatz and ProcDump. |
| T1003.001 LSASS Memory |
GroupVolt Typhoon | Volt Typhoon has attempted to access hashed credentials from the LSASS process memory space. |
| T1003.001 LSASS Memory |
GroupAPT41 | APT41 has used hashdump, Mimikatz, Procdump, and the Windows Credential Editor to dump password hashes from memory and authenticate to other user accounts. |
| T1003.001 LSASS Memory |
GroupAPT32 | APT32 used Mimikatz and customized versions of Windows Credential Dumper to harvest credentials. |
| T1003.001 LSASS Memory |
GroupHAFNIUM | HAFNIUM has used |
| T1003.001 LSASS Memory |
GroupMuddyWater | MuddyWater has performed credential dumping with Mimikatz and procdump64.exe. |
| T1003.001 LSASS Memory |
GroupFIN6 | FIN6 has used Windows Credential Editor for credential dumping. |
| T1003.001 LSASS Memory |
GroupLeafminer | Leafminer used several tools for retrieving login and password information, including LaZagne and Mimikatz. |
| T1003.001 LSASS Memory |
GroupSandworm Team | Sandworm Team has used its plainpwd tool, a modified version of Mimikatz, and comsvcs.dll to dump Windows credentials from system memory. |
| T1003.001 LSASS Memory |
GroupMustang Panda | Mustang Panda has harvested credentials from memory of lssas.exe with Mimikatz. |
| T1003.001 LSASS Memory |
GroupAPT39 | APT39 has used Mimikatz, Windows Credential Editor and ProcDump to dump credentials. |
| T1003.001 LSASS Memory |
GroupUNC3886 | UNC3886 has used MiniDump to dump process memory and search for cleartext credentials. |
| T1003.001 LSASS Memory |
GroupOilRig | OilRig has used credential dumping tools such as Mimikatz to steal credentials to accounts logged into the compromised system and to Outlook Web Access. |
| T1003.001 LSASS Memory |
GroupAquatic Panda | Aquatic Panda has attempted to harvest credentials through LSASS memory dumping. |
| T1003.001 LSASS Memory |
GroupKe3chang | Ke3chang has dumped credentials, including by using Mimikatz. |
| T1003.001 LSASS Memory |
GroupAPT1 | APT1 has been known to use credential dumping using Mimikatz. |
| T1003.001 LSASS Memory |
GroupLeviathan | Leviathan has used publicly available tools to dump password hashes, including ProcDump and WCE. |
| T1003.001 LSASS Memory |
GroupBlue Mockingbird | Blue Mockingbird has used Mimikatz to retrieve credentials from LSASS memory. |
| T1003.001 LSASS Memory |
GroupRedCurl | |
| T1003.001 LSASS Memory |
GroupMirrorFace | MirrorFace has dumped LSASS memory for credential access. |
| T1003.001 LSASS Memory |
GroupCleaver | Cleaver has been known to dump credentials using Mimikatz and Windows Credential Editor. |
| T1003.001 LSASS Memory |
GroupMedusa Group | Medusa Group has leveraged Mimikatz to dump LSASS to harvest credentials. |
| T1003.001 LSASS Memory |
GroupBRONZE BUTLER | BRONZE BUTLER has used various tools (such as Mimikatz and WCE) to perform credential dumping. |
| T1003.001 LSASS Memory |
GroupEmber Bear | Ember Bear uses legitimate Sysinternals tools such as procdump to dump LSASS memory. |
| T1003.001 LSASS Memory |
GroupWhitefly | |
| T1003.001 LSASS Memory |
GroupAgrius | Agrius used tools such as Mimikatz to dump LSASS memory to capture credentials in victim environments. |
| T1003.001 LSASS Memory |
GroupAPT28 | APT28 regularly deploys both publicly available (ex: Mimikatz) and custom password retrieval tools on victims. They have also dumped the LSASS process memory using the MiniDump function. |
| T1003.001 LSASS Memory |
GroupAPT5 | APT5 has used the Task Manager process to target LSASS process memory in order to obtain NTLM password hashes. APT5 has also dumped clear text passwords and hashes from memory using Mimikatz hosted through an RDP mapped drive. |
| T1003.001 LSASS Memory |
GroupFox Kitten | Fox Kitten has used prodump to dump credentials from LSASS. |
| T1003.001 LSASS Memory |
GroupEarth Lusca | Earth Lusca has used ProcDump to obtain the hashes of credentials by dumping the memory of the LSASS process. |
| T1003.001 LSASS Memory |
GroupSilence | Silence has used the Farse6.1 utility (based on Mimikatz) to extract credentials from lsass.exe. |
| T1003.001 LSASS Memory |
GroupWizard Spider | Wizard Spider has dumped the lsass.exe memory to harvest credentials with the use of open-source tool LaZagne. |
| T1003.001 LSASS Memory |
GroupMoonstone Sleet | Moonstone Sleet retrieved credentials from LSASS memory. |
| T1003.001 LSASS Memory |
GroupVOID MANTICORE | VOID MANTICORE has dumped LSASS credentials using `comsvcs.dll` via `rundll32.exe`. |
| T1003.001 LSASS Memory |
GroupPlay | Play has used Mimikatz and the Windows Task Manager to dump LSASS process memory. |
| T1003.001 LSASS Memory |
GroupPLATINUM | PLATINUM has used keyloggers that are also capable of dumping credentials. |
| T1003.001 LSASS Memory |
GroupMagic Hound | Magic Hound has stolen domain credentials by dumping LSASS process memory using Task Manager, comsvcs.dll, and from a Microsoft Active Directory Domain Controller using Mimikatz. |
| T1003.001 LSASS Memory |
GroupThreat Group-3390 | Threat Group-3390 actors have used a modified version of Mimikatz called Wrapikatz to dump credentials. They have also dumped credentials from domain controllers. |
| T1003.001 LSASS Memory |
GroupAPT33 | APT33 has used a variety of publicly available tools like LaZagne, Mimikatz, and ProcDump to dump credentials. |
| T1003.001 LSASS Memory |
GroupFIN8 | FIN8 harvests credentials using Invoke-Mimikatz or Windows Credentials Editor (WCE). |
| T1003.001 LSASS Memory |
GroupFIN13 | FIN13 has obtained memory dumps with ProcDump to parse and extract credentials from a victim's LSASS process memory with Mimikatz. |
| T1003.001 LSASS Memory |
MalwareBad Rabbit | Bad Rabbit has used Mimikatz to harvest credentials from the victim's machine. |
| T1003.001 LSASS Memory |
MalwareGreyEnergy | GreyEnergy has a module for Mimikatz to collect Windows credentials from the victim’s machine. |
| T1003.001 LSASS Memory |
MalwareEmotet | Emotet has been observed dropping and executing password grabber modules including Mimikatz. |
| T1003.001 LSASS Memory |
MalwareOlympic Destroyer | Olympic Destroyer contains a module that tries to obtain credentials from LSASS, similar to Mimikatz. These credentials are used with PsExec and Windows Management Instrumentation to help the malware propagate itself across a network. |
| T1003.001 LSASS Memory |
MalwareMafalda | Mafalda can dump password hashes from `LSASS.exe`. |
| T1003.001 LSASS Memory |
MalwareOkrum | Okrum was seen using MimikatzLite to perform credential dumping. |
| T1003.001 LSASS Memory |
MalwareNotPetya | NotPetya contains a modified version of Mimikatz to help gather credentials that are later used for lateral movement. |
| T1003.001 LSASS Memory |
MalwarePysa | |
| T1003.001 LSASS Memory |
MalwareCobalt Strike | Cobalt Strike can spawn a job to inject into LSASS memory and dump password hashes. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.