ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
MalwareDaserf

Daserf leverages Mimikatz and Windows Credential Editor to steal credentials.

T1003.001
LSASS Memory
MalwarePoetRAT

PoetRAT used voStro.exe, a compiled pypykatz (Python version of Mimikatz), to steal credentials.

T1003.001
LSASS Memory
MalwareQilin

Qilin can employ an embedded Mimikatz module to dump LSASS memory.

T1003.001
LSASS Memory
MalwareCozyCar

CozyCar has executed Mimikatz to harvest stored credentials from the victim and further victim penetration.

T1003.001
LSASS Memory
MalwareLizar

Lizar can run Mimikatz to harvest credentials.

T1003.001
LSASS Memory
MalwareNet Crawler

Net Crawler uses credential dumpers such as Mimikatz and Windows Credential Editor to extract cached credentials from Windows systems.

T1003.001
LSASS Memory
ToolSliver

Sliver has a built-in `procdump` command allowing for retrieval of memory from processes such as `lsass.exe` for credential harvesting.

T1003.001
LSASS Memory
ToolSILENTTRINITY

SILENTTRINITY can create a memory dump of LSASS via the `MiniDumpWriteDump Win32` API call.

T1003.001
LSASS Memory
ToolPowerSploit

PowerSploit contains a collection of Exfiltration modules that can harvest credentials using Mimikatz.

T1003.001
LSASS Memory
ToolWindows Credential Editor

Windows Credential Editor can dump credentials.

T1003.001
LSASS Memory
ToolImpacket

SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information.

T1003.001
LSASS Memory
ToolLslsass

Lslsass can dump active logon session password hashes from the lsass process.

T1003.001
LSASS Memory
ToolEmpire

Empire contains an implementation of Mimikatz to gather credentials from memory.

T1003.001
LSASS Memory
ToolPoshC2

PoshC2 contains an implementation of Mimikatz to gather credentials from memory.

T1003.001
LSASS Memory
ToolMimikatz

Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the LSASS Memory.

T1003.001
LSASS Memory
ToolLaZagne

LaZagne can perform credential dumping from memory to obtain account and password information.

T1003.001
LSASS Memory
ToolPupy

Pupy can execute Lazagne as well as Mimikatz using PowerShell.

T1003.002
Security Account Manager
CampaignFrostyGoop Incident

During FrostyGoop Incident, the adversary retrieved the contents of the Security Account Manager (SAM) hive in the victim environment for credential capture.

T1003.002
Security Account Manager
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used `reg save` to retrieve credentials from the Security Account Manager (SAM) database.

T1003.002
Security Account Manager
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors leveraged a custom tool to dump OS credentials and used following commands: `reg save HKLM\\SYSTEM system.hiv`, `reg save HKLM\\SAM sam.hiv`, and `reg save HKLM\\SECURITY security.hiv`, to dump SAM, SYSTEM and SECURITY hives.

T1003.002
Security Account Manager
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 used the following commands to dump SAM, SYSTEM, and SECURITY hives: reg save hklm\sam, reg save hklm\system, and reg save hklm\security.

T1003.002
Security Account Manager
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries had stolen Security Account Manager (SAM) and SYSTEM registry hives.

T1003.002
Security Account Manager
CampaignNight Dragon

During Night Dragon, threat actors dumped account hashes using gsecdump.

T1003.002
Security Account Manager
CampaignC0017

During C0017, APT41 copied the `SAM` and `SYSTEM` Registry hives for credential harvesting.

T1003.002
Security Account Manager
GroupGALLIUM

GALLIUM used reg commands to dump specific hives from the Windows Registry, such as the SAM hive, and obtain password hashes.

T1003.002
Security Account Manager
GroupAPT41

APT41 extracted user account data from the Security Account Managerr (SAM), making a copy of this database from the registry using the reg save command or by exploiting volume shadow copies.

T1003.002
Security Account Manager
GroupDragonfly

Dragonfly has dropped and executed SecretsDump to dump password hashes.

T1003.002
Security Account Manager
GroupmenuPass

menuPass has used a modified version of pentesting tools wmiexec.vbs and secretsdump.py to dump credentials.

T1003.002
Security Account Manager
GroupKe3chang

Ke3chang has dumped credentials, including by using gsecdump.

T1003.002
Security Account Manager
GroupAPT29

APT29 has used the `reg save` command to save registry hives.

T1003.002
Security Account Manager
GroupMirrorFace

MirrorFace has used vssadmin to copy registry hives including SAM.

T1003.002
Security Account Manager
GroupEmber Bear

Ember Bear acquires victim credentials by extracting registry hives such as the Security Account Manager through commands such as reg save.

T1003.002
Security Account Manager
GroupAgrius

Agrius dumped the SAM file on victim machines to capture credentials.

T1003.002
Security Account Manager
GroupAPT5

APT5 has copied and exfiltrated the SAM Registry hive from targeted systems.

T1003.002
Security Account Manager
GroupWizard Spider

Wizard Spider has acquired credentials from the SAM/SECURITY registry hives.

T1003.002
Security Account Manager
GroupDaggerfly

Daggerfly used Reg to dump the Security Account Manager (SAM) hive from victim machines for follow-on credential extraction.

T1003.002
Security Account Manager
GroupThreat Group-3390

Threat Group-3390 actors have used gsecdump to dump credentials. They have also dumped credentials from domain controllers.

T1003.002
Security Account Manager
GroupFIN13

FIN13 has extracted the SAM and SYSTEM registry hives using the `reg.exe` binary for obtaining password hashes from a compromised machine.

T1003.002
Security Account Manager
MalwareCosmicDuke

CosmicDuke collects Windows account hashes.

T1003.002
Security Account Manager
MalwareHOPLIGHT

HOPLIGHT has the capability to harvest credentials and passwords from the SAM database.

T1003.002
Security Account Manager
MalwareRemsec

Remsec can dump the SAM database.

T1003.002
Security Account Manager
MalwareCobalt Strike

Cobalt Strike can recover hashed passwords.

T1003.002
Security Account Manager
MalwareIceApple

IceApple's Credential Dumper module can dump encrypted password hashes from SAM registry keys, including `HKLM\SAM\SAM\Domains\Account\F` and `HKLM\SAM\SAM\Domains\Account\Users\*\V`.

T1003.002
Security Account Manager
MalwareCozyCar

Password stealer and NTLM stealer modules in CozyCar harvest stored credentials from the victim, including credentials used as part of Windows NTLM user authentication.

T1003.002
Security Account Manager
MalwarePOWERTON

POWERTON has the ability to dump password hashes.

T1003.002
Security Account Manager
MalwareMivast

Mivast has the capability to gather NTLM password information.

T1003.002
Security Account Manager
ToolImpacket

SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information.

T1003.002
Security Account Manager
ToolFgdump

Fgdump can dump Windows password hashes.

T1003.002
Security Account Manager
Toolpwdump

pwdump can be used to dump credentials from the SAM.

T1003.002
Security Account Manager
ToolMimikatz

Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the SAM table.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.