Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
MalwareDaserf | Daserf leverages Mimikatz and Windows Credential Editor to steal credentials. |
| T1003.001 LSASS Memory |
MalwarePoetRAT | PoetRAT used voStro.exe, a compiled pypykatz (Python version of Mimikatz), to steal credentials. |
| T1003.001 LSASS Memory |
MalwareQilin | Qilin can employ an embedded Mimikatz module to dump LSASS memory. |
| T1003.001 LSASS Memory |
MalwareCozyCar | CozyCar has executed Mimikatz to harvest stored credentials from the victim and further victim penetration. |
| T1003.001 LSASS Memory |
MalwareLizar | |
| T1003.001 LSASS Memory |
MalwareNet Crawler | Net Crawler uses credential dumpers such as Mimikatz and Windows Credential Editor to extract cached credentials from Windows systems. |
| T1003.001 LSASS Memory |
ToolSliver | Sliver has a built-in `procdump` command allowing for retrieval of memory from processes such as `lsass.exe` for credential harvesting. |
| T1003.001 LSASS Memory |
ToolSILENTTRINITY | SILENTTRINITY can create a memory dump of LSASS via the `MiniDumpWriteDump Win32` API call. |
| T1003.001 LSASS Memory |
ToolPowerSploit | PowerSploit contains a collection of Exfiltration modules that can harvest credentials using Mimikatz. |
| T1003.001 LSASS Memory |
ToolWindows Credential Editor | Windows Credential Editor can dump credentials. |
| T1003.001 LSASS Memory |
ToolImpacket | SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information. |
| T1003.001 LSASS Memory |
ToolLslsass | Lslsass can dump active logon session password hashes from the lsass process. |
| T1003.001 LSASS Memory |
ToolEmpire | Empire contains an implementation of Mimikatz to gather credentials from memory. |
| T1003.001 LSASS Memory |
ToolPoshC2 | PoshC2 contains an implementation of Mimikatz to gather credentials from memory. |
| T1003.001 LSASS Memory |
ToolMimikatz | Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the LSASS Memory. |
| T1003.001 LSASS Memory |
ToolLaZagne | LaZagne can perform credential dumping from memory to obtain account and password information. |
| T1003.001 LSASS Memory |
ToolPupy | Pupy can execute Lazagne as well as Mimikatz using PowerShell. |
| T1003.002 Security Account Manager |
CampaignFrostyGoop Incident | During FrostyGoop Incident, the adversary retrieved the contents of the Security Account Manager (SAM) hive in the victim environment for credential capture. |
| T1003.002 Security Account Manager |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used `reg save` to retrieve credentials from the Security Account Manager (SAM) database. |
| T1003.002 Security Account Manager |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors leveraged a custom tool to dump OS credentials and used following commands: `reg save HKLM\\SYSTEM system.hiv`, `reg save HKLM\\SAM sam.hiv`, and `reg save HKLM\\SECURITY security.hiv`, to dump SAM, SYSTEM and SECURITY hives. |
| T1003.002 Security Account Manager |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 used the following commands to dump SAM, SYSTEM, and SECURITY hives: |
| T1003.002 Security Account Manager |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries had stolen Security Account Manager (SAM) and SYSTEM registry hives. |
| T1003.002 Security Account Manager |
CampaignNight Dragon | During Night Dragon, threat actors dumped account hashes using gsecdump. |
| T1003.002 Security Account Manager |
CampaignC0017 | During C0017, APT41 copied the `SAM` and `SYSTEM` Registry hives for credential harvesting. |
| T1003.002 Security Account Manager |
GroupGALLIUM | GALLIUM used |
| T1003.002 Security Account Manager |
GroupAPT41 | APT41 extracted user account data from the Security Account Managerr (SAM), making a copy of this database from the registry using the |
| T1003.002 Security Account Manager |
GroupDragonfly | Dragonfly has dropped and executed SecretsDump to dump password hashes. |
| T1003.002 Security Account Manager |
GroupmenuPass | menuPass has used a modified version of pentesting tools wmiexec.vbs and secretsdump.py to dump credentials. |
| T1003.002 Security Account Manager |
GroupKe3chang | Ke3chang has dumped credentials, including by using gsecdump. |
| T1003.002 Security Account Manager |
GroupAPT29 | APT29 has used the `reg save` command to save registry hives. |
| T1003.002 Security Account Manager |
GroupMirrorFace | MirrorFace has used vssadmin to copy registry hives including SAM. |
| T1003.002 Security Account Manager |
GroupEmber Bear | Ember Bear acquires victim credentials by extracting registry hives such as the Security Account Manager through commands such as |
| T1003.002 Security Account Manager |
GroupAgrius | Agrius dumped the SAM file on victim machines to capture credentials. |
| T1003.002 Security Account Manager |
GroupAPT5 | APT5 has copied and exfiltrated the SAM Registry hive from targeted systems. |
| T1003.002 Security Account Manager |
GroupWizard Spider | Wizard Spider has acquired credentials from the SAM/SECURITY registry hives. |
| T1003.002 Security Account Manager |
GroupDaggerfly | Daggerfly used Reg to dump the Security Account Manager (SAM) hive from victim machines for follow-on credential extraction. |
| T1003.002 Security Account Manager |
GroupThreat Group-3390 | Threat Group-3390 actors have used gsecdump to dump credentials. They have also dumped credentials from domain controllers. |
| T1003.002 Security Account Manager |
GroupFIN13 | FIN13 has extracted the SAM and SYSTEM registry hives using the `reg.exe` binary for obtaining password hashes from a compromised machine. |
| T1003.002 Security Account Manager |
MalwareCosmicDuke | CosmicDuke collects Windows account hashes. |
| T1003.002 Security Account Manager |
MalwareHOPLIGHT | HOPLIGHT has the capability to harvest credentials and passwords from the SAM database. |
| T1003.002 Security Account Manager |
MalwareRemsec | Remsec can dump the SAM database. |
| T1003.002 Security Account Manager |
MalwareCobalt Strike | Cobalt Strike can recover hashed passwords. |
| T1003.002 Security Account Manager |
MalwareIceApple | IceApple's Credential Dumper module can dump encrypted password hashes from SAM registry keys, including `HKLM\SAM\SAM\Domains\Account\F` and `HKLM\SAM\SAM\Domains\Account\Users\*\V`. |
| T1003.002 Security Account Manager |
MalwareCozyCar | Password stealer and NTLM stealer modules in CozyCar harvest stored credentials from the victim, including credentials used as part of Windows NTLM user authentication. |
| T1003.002 Security Account Manager |
MalwarePOWERTON | POWERTON has the ability to dump password hashes. |
| T1003.002 Security Account Manager |
MalwareMivast | Mivast has the capability to gather NTLM password information. |
| T1003.002 Security Account Manager |
ToolImpacket | SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information. |
| T1003.002 Security Account Manager |
ToolFgdump | Fgdump can dump Windows password hashes. |
| T1003.002 Security Account Manager |
Toolpwdump | pwdump can be used to dump credentials from the SAM. |
| T1003.002 Security Account Manager |
ToolMimikatz | Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the SAM table. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.