Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.002 Security Account Manager |
Toolgsecdump | gsecdump can dump Windows password hashes from the SAM. |
| T1003.002 Security Account Manager |
ToolCrackMapExec | CrackMapExec can dump usernames and hashed passwords from the SAM. |
| T1003.002 Security Account Manager |
ToolKoadic | Koadic can gather hashed passwords by dumping SAM/SECURITY hive. |
| T1003.003 NTDS |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors obtained active directory credentials via the NTDS.DIT file. |
| T1003.003 NTDS |
CampaignCutting Edge | During Cutting Edge, threat actors accessed and mounted virtual hard disk backups to extract |
| T1003.003 NTDS |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 dumped NTDS.dit through creating volume shadow copies via |
| T1003.003 NTDS |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries dumped the entire Active Directory database by extracting the contents of the ntds.dit file. |
| T1003.003 NTDS |
GroupVolt Typhoon | Volt Typhoon has used ntds.util to create domain controller installation media containing usernames and password hashes. |
| T1003.003 NTDS |
GroupAPT41 | APT41 used ntdsutil to obtain a copy of the victim environment |
| T1003.003 NTDS |
GroupDragonfly | Dragonfly has dropped and executed SecretsDump to dump password hashes. They also obtained ntds.dit from domain controllers. |
| T1003.003 NTDS |
GroupmenuPass | menuPass has used Ntdsutil to dump credentials. |
| T1003.003 NTDS |
GroupHAFNIUM | HAFNIUM has stolen copies of the Active Directory database (NTDS.DIT). |
| T1003.003 NTDS |
GroupFIN6 | FIN6 has used Metasploit’s PsExec NTDSGRAB module to obtain a copy of the victim's Active Directory database. |
| T1003.003 NTDS |
GroupSandworm Team | Sandworm Team has used `ntdsutil.exe` to back up the Active Directory database, likely for credential access. |
| T1003.003 NTDS |
GroupMustang Panda | Mustang Panda has used vssadmin to create a volume shadow copy and retrieve the NTDS.dit file. Mustang Panda has also used |
| T1003.003 NTDS |
GroupScattered Spider | Scattered Spider has extracted the `NTDS.dit` file by creating volume shadow copies of virtual domain controller disks. |
| T1003.003 NTDS |
GroupKe3chang | Ke3chang has used NTDSDump and other password dumping tools to gather credentials. |
| T1003.003 NTDS |
GroupChimera | Chimera has gathered the SYSTEM registry and ntds.dit files from target systems. Chimera specifically has used the NtdsAudit tool to dump the password hashes of domain users via |
| T1003.003 NTDS |
GroupMirrorFace | MirrorFace has dumped NTDS.dit through volume shadow copies. |
| T1003.003 NTDS |
GroupMedusa Group | Medusa Group has accessed the ntds.dit file to engage in credential dumping. |
| T1003.003 NTDS |
GroupAPT28 | APT28 has used the ntdsutil.exe utility to export the Active Directory database for credential access. |
| T1003.003 NTDS |
GroupFox Kitten | Fox Kitten has used Volume Shadow Copy to access credential information from NTDS. |
| T1003.003 NTDS |
GroupLAPSUS$ | LAPSUS$ has used Windows built-in tool `ntdsutil` to extract the Active Directory (AD) database. |
| T1003.003 NTDS |
GroupWizard Spider | Wizard Spider has gained access to credentials via exported copies of the ntds.dit Active Directory database. Wizard Spider has also created a volume shadow copy and used a batch script file to collect NTDS.dit with the use of the Windows utility, ntdsutil. |
| T1003.003 NTDS |
GroupFIN13 | FIN13 has harvested the NTDS.DIT file and leveraged the Impacket tool on the compromised domain controller to locally decrypt it. |
| T1003.003 NTDS |
ToolImpacket | SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information from NTDS.dit. |
| T1003.003 NTDS |
Toolesentutl | esentutl can copy `ntds.dit` using the Volume Shadow Copy service. |
| T1003.003 NTDS |
ToolCrackMapExec | CrackMapExec can dump hashed passwords associated with Active Directory using Windows' Directory Replication Services API (DRSUAPI), or Volume Shadow Copy. |
| T1003.003 NTDS |
ToolKoadic | Koadic can gather hashed passwords by gathering domain controller hashes from NTDS. |
| T1003.004 LSA Secrets |
GroupDragonfly | Dragonfly has dropped and executed SecretsDump to dump password hashes. |
| T1003.004 LSA Secrets |
GroupmenuPass | menuPass has used a modified version of pentesting tools wmiexec.vbs and secretsdump.py to dump credentials. |
| T1003.004 LSA Secrets |
GroupMuddyWater | MuddyWater has performed credential dumping with LaZagne. |
| T1003.004 LSA Secrets |
GroupLeafminer | Leafminer used several tools for retrieving login and password information, including LaZagne. |
| T1003.004 LSA Secrets |
GroupOilRig | OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. |
| T1003.004 LSA Secrets |
GroupKe3chang | Ke3chang has dumped credentials, including by using gsecdump. |
| T1003.004 LSA Secrets |
GroupAPT29 | APT29 has used the `reg save` command to extract LSA secrets offline. |
| T1003.004 LSA Secrets |
GroupEmber Bear | Ember Bear has used frameworks such as Impacket to dump LSA secrets for credential capture. |
| T1003.004 LSA Secrets |
GroupThreat Group-3390 | Threat Group-3390 actors have used gsecdump to dump credentials. They have also dumped credentials from domain controllers. |
| T1003.004 LSA Secrets |
GroupAPT33 | APT33 has used a variety of publicly available tools like LaZagne to gather credentials. |
| T1003.004 LSA Secrets |
MalwareCosmicDuke | CosmicDuke collects LSA secrets. |
| T1003.004 LSA Secrets |
MalwareIceApple | IceApple's Credential Dumper module can dump LSA secrets from registry keys, including: `HKLM\SECURITY\Policy\PolEKList\default`, `HKLM\SECURITY\Policy\Secrets\*\CurrVal`, and `HKLM\SECURITY\Policy\Secrets\*\OldVal`. |
| T1003.004 LSA Secrets |
ToolImpacket | SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information. |
| T1003.004 LSA Secrets |
ToolAADInternals | AADInternals can dump secrets from the Local Security Authority. |
| T1003.004 LSA Secrets |
ToolMimikatz | Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the LSA. |
| T1003.004 LSA Secrets |
Toolgsecdump | gsecdump can dump LSA secrets. |
| T1003.004 LSA Secrets |
ToolLaZagne | LaZagne can perform credential dumping from LSA secrets to obtain account and password information. |
| T1003.004 LSA Secrets |
ToolCrackMapExec | CrackMapExec can dump hashed passwords from LSA secrets for the targeted system. |
| T1003.004 LSA Secrets |
ToolPupy | Pupy can use Lazagne for harvesting credentials. |
| T1003.005 Cached Domain Credentials |
GroupMuddyWater | MuddyWater has performed credential dumping with LaZagne. |
| T1003.005 Cached Domain Credentials |
GroupLeafminer | Leafminer used several tools for retrieving login and password information, including LaZagne. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.