Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.002 Security Account Manager |
ToolImpacket | SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information. |
| T1003.002 Security Account Manager |
ToolFgdump | Fgdump can dump Windows password hashes. |
| T1003.002 Security Account Manager |
Toolpwdump | pwdump can be used to dump credentials from the SAM. |
| T1003.002 Security Account Manager |
ToolMimikatz | Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the SAM table. |
| T1003.002 Security Account Manager |
Toolgsecdump | gsecdump can dump Windows password hashes from the SAM. |
| T1003.002 Security Account Manager |
ToolCrackMapExec | CrackMapExec can dump usernames and hashed passwords from the SAM. |
| T1003.002 Security Account Manager |
ToolKoadic | Koadic can gather hashed passwords by dumping SAM/SECURITY hive. |
| T1003.003 NTDS |
ToolImpacket | SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information from NTDS.dit. |
| T1003.003 NTDS |
Toolesentutl | esentutl can copy `ntds.dit` using the Volume Shadow Copy service. |
| T1003.003 NTDS |
ToolCrackMapExec | CrackMapExec can dump hashed passwords associated with Active Directory using Windows' Directory Replication Services API (DRSUAPI), or Volume Shadow Copy. |
| T1003.003 NTDS |
ToolKoadic | Koadic can gather hashed passwords by gathering domain controller hashes from NTDS. |
| T1003.004 LSA Secrets |
MalwareCosmicDuke | CosmicDuke collects LSA secrets. |
| T1003.004 LSA Secrets |
MalwareIceApple | IceApple's Credential Dumper module can dump LSA secrets from registry keys, including: `HKLM\SECURITY\Policy\PolEKList\default`, `HKLM\SECURITY\Policy\Secrets\*\CurrVal`, and `HKLM\SECURITY\Policy\Secrets\*\OldVal`. |
| T1003.004 LSA Secrets |
ToolImpacket | SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information. |
| T1003.004 LSA Secrets |
ToolAADInternals | AADInternals can dump secrets from the Local Security Authority. |
| T1003.004 LSA Secrets |
ToolMimikatz | Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the LSA. |
| T1003.004 LSA Secrets |
Toolgsecdump | gsecdump can dump LSA secrets. |
| T1003.004 LSA Secrets |
ToolLaZagne | LaZagne can perform credential dumping from LSA secrets to obtain account and password information. |
| T1003.004 LSA Secrets |
ToolCrackMapExec | CrackMapExec can dump hashed passwords from LSA secrets for the targeted system. |
| T1003.004 LSA Secrets |
ToolPupy | Pupy can use Lazagne for harvesting credentials. |
| T1003.005 Cached Domain Credentials |
MalwareOkrum | Okrum was seen using modified Quarks PwDump to perform credential dumping. |
| T1003.005 Cached Domain Credentials |
ToolLaZagne | LaZagne can perform credential dumping from MSCache to obtain account and password information. |
| T1003.005 Cached Domain Credentials |
ToolCachedump | Cachedump can extract cached password hashes from cache entry information. |
| T1003.005 Cached Domain Credentials |
ToolPupy | Pupy can use Lazagne for harvesting credentials. |
| T1003.006 DCSync |
ToolMimikatz | Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from DCSync/NetSync. |
| T1003.007 Proc Filesystem |
MalwarePACEMAKER | PACEMAKER has the ability to extract credentials from OS memory. |
| T1003.007 Proc Filesystem |
ToolMimiPenguin | MimiPenguin can use the `<PID>/maps` and `<PID>/mem` file to search for regex patterns and dump the process memory. |
| T1003.007 Proc Filesystem |
ToolLaZagne | LaZagne can use the `<PID>/maps` and `<PID>/mem` files to identify regex patterns to dump cleartext passwords from the browser's process memory. |
| T1003.007 Proc Filesystem |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can scrape memory from the Runner.Worker process by reading `/proc/<pid>/mem` to extract secrets including plaintext tokens. |
| T1003.007 Proc Filesystem |
MalwareMini Shai-Hulud | Mini Shai-Hulud has scraped runner process memory to extract short-lived identity tokens, which it then exchanged for per-package npm trusted-publisher tokens. |
| T1003.008 /etc/passwd and /etc/shadow |
ToolLaZagne | LaZagne can obtain credential information from /etc/shadow using the shadow.py module. |
| T1005 Data from Local System |
MalwareTrickBot | TrickBot collects local files and information from the victim’s local machine. |
| T1005 Data from Local System |
MalwareBLINDINGCAN | BLINDINGCAN has uploaded files from victim machines. |
| T1005 Data from Local System |
MalwareRCSession | RCSession can collect data from a compromised host. |
| T1005 Data from Local System |
MalwareQuietSieve | QuietSieve can collect files from a compromised host. |
| T1005 Data from Local System |
MalwareBumblebee | Bumblebee can capture and compress stolen credentials from the Registry and volume shadow copies. |
| T1005 Data from Local System |
MalwareBRICKSTORM | BRICKSTORM has commands that allow the actor download files from the compromised host to the C2 server, and to also download specific sections of a file. |
| T1005 Data from Local System |
MalwareAmadey | Amadey can collect information from a compromised host. |
| T1005 Data from Local System |
MalwareProxysvc | Proxysvc searches the local system and gathers data. |
| T1005 Data from Local System |
Malwareyty | yty collects files with the following extensions: .ppt, .pptx, .pdf, .doc, .docx, .xls, .xlsx, .docm, .rtf, .inp, .xlsm, .csv, .odt, .pps, .vcf and sends them back to the C2 server. |
| T1005 Data from Local System |
MalwareKOPILUWAK | KOPILUWAK can gather information from compromised hosts. |
| T1005 Data from Local System |
MalwareSardonic | Sardonic has the ability to collect data from a compromised machine to deliver to the attacker. |
| T1005 Data from Local System |
MalwareMisdat | Misdat has collected files and data from a compromised host. |
| T1005 Data from Local System |
MalwareUrsnif | Ursnif has collected files from victim machines, including certificates and cookies. |
| T1005 Data from Local System |
MalwareCASTLETAP | CASTLETAP can execute a C2 command to transfer files from victim machines. |
| T1005 Data from Local System |
MalwareThreatNeedle | ThreatNeedle can collect data and files from a compromised host. |
| T1005 Data from Local System |
MalwareHavoc | Havoc can download files from the victim's computer. |
| T1005 Data from Local System |
MalwareFrameworkPOS | FrameworkPOS can collect elements related to credit card data from process memory. |
| T1005 Data from Local System |
MalwareGravityRAT | GravityRAT steals files with the following extensions: .docx, .doc, .pptx, .ppt, .xlsx, .xls, .rtf, and .pdf. |
| T1005 Data from Local System |
MalwareInvisibleFerret | InvisibleFerret has collected data utilizing a script that contained a list of excluded files and directory names and naming patterns of interest such as environment and configuration files, documents, spreadsheets, and other files that contained the words secret, wallet, private, and password. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.