ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1003.002
Security Account Manager
Toolgsecdump

gsecdump can dump Windows password hashes from the SAM.

T1003.002
Security Account Manager
ToolCrackMapExec

CrackMapExec can dump usernames and hashed passwords from the SAM.

T1003.002
Security Account Manager
ToolKoadic

Koadic can gather hashed passwords by dumping SAM/SECURITY hive.

T1003.003
NTDS
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors obtained active directory credentials via the NTDS.DIT file.

T1003.003
NTDS
CampaignCutting Edge

During Cutting Edge, threat actors accessed and mounted virtual hard disk backups to extract
ntds.dit.

T1003.003
NTDS
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 dumped NTDS.dit through creating volume shadow copies via vssadmin.

T1003.003
NTDS
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries dumped the entire Active Directory database by extracting the contents of the ntds.dit file.

T1003.003
NTDS
GroupVolt Typhoon

Volt Typhoon has used ntds.util to create domain controller installation media containing usernames and password hashes.

T1003.003
NTDS
GroupAPT41

APT41 used ntdsutil to obtain a copy of the victim environment ntds.dit file.

T1003.003
NTDS
GroupDragonfly

Dragonfly has dropped and executed SecretsDump to dump password hashes. They also obtained ntds.dit from domain controllers.

T1003.003
NTDS
GroupmenuPass

menuPass has used Ntdsutil to dump credentials.

T1003.003
NTDS
GroupHAFNIUM

HAFNIUM has stolen copies of the Active Directory database (NTDS.DIT).

T1003.003
NTDS
GroupFIN6

FIN6 has used Metasploit’s PsExec NTDSGRAB module to obtain a copy of the victim's Active Directory database.

T1003.003
NTDS
GroupSandworm Team

Sandworm Team has used `ntdsutil.exe` to back up the Active Directory database, likely for credential access.

T1003.003
NTDS
GroupMustang Panda

Mustang Panda has used vssadmin to create a volume shadow copy and retrieve the NTDS.dit file. Mustang Panda has also used reg save on the SYSTEM file Registry location to help extract the NTDS.dit file.

T1003.003
NTDS
GroupScattered Spider

Scattered Spider has extracted the `NTDS.dit` file by creating volume shadow copies of virtual domain controller disks.

T1003.003
NTDS
GroupKe3chang

Ke3chang has used NTDSDump and other password dumping tools to gather credentials.

T1003.003
NTDS
GroupChimera

Chimera has gathered the SYSTEM registry and ntds.dit files from target systems. Chimera specifically has used the NtdsAudit tool to dump the password hashes of domain users via msadcs.exe "NTDS.dit" -s "SYSTEM" -p RecordedTV_pdmp.txt --users-csv RecordedTV_users.csv and used ntdsutil to copy the Active Directory database.

T1003.003
NTDS
GroupMirrorFace

MirrorFace has dumped NTDS.dit through volume shadow copies.

T1003.003
NTDS
GroupMedusa Group

Medusa Group has accessed the ntds.dit file to engage in credential dumping.

T1003.003
NTDS
GroupAPT28

APT28 has used the ntdsutil.exe utility to export the Active Directory database for credential access.

T1003.003
NTDS
GroupFox Kitten

Fox Kitten has used Volume Shadow Copy to access credential information from NTDS.

T1003.003
NTDS
GroupLAPSUS$

LAPSUS$ has used Windows built-in tool `ntdsutil` to extract the Active Directory (AD) database.

T1003.003
NTDS
GroupWizard Spider

Wizard Spider has gained access to credentials via exported copies of the ntds.dit Active Directory database. Wizard Spider has also created a volume shadow copy and used a batch script file to collect NTDS.dit with the use of the Windows utility, ntdsutil.

T1003.003
NTDS
GroupFIN13

FIN13 has harvested the NTDS.DIT file and leveraged the Impacket tool on the compromised domain controller to locally decrypt it.

T1003.003
NTDS
ToolImpacket

SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information from NTDS.dit.

T1003.003
NTDS
Toolesentutl

esentutl can copy `ntds.dit` using the Volume Shadow Copy service.

T1003.003
NTDS
ToolCrackMapExec

CrackMapExec can dump hashed passwords associated with Active Directory using Windows' Directory Replication Services API (DRSUAPI), or Volume Shadow Copy.

T1003.003
NTDS
ToolKoadic

Koadic can gather hashed passwords by gathering domain controller hashes from NTDS.

T1003.004
LSA Secrets
GroupDragonfly

Dragonfly has dropped and executed SecretsDump to dump password hashes.

T1003.004
LSA Secrets
GroupmenuPass

menuPass has used a modified version of pentesting tools wmiexec.vbs and secretsdump.py to dump credentials.

T1003.004
LSA Secrets
GroupMuddyWater

MuddyWater has performed credential dumping with LaZagne.

T1003.004
LSA Secrets
GroupLeafminer

Leafminer used several tools for retrieving login and password information, including LaZagne.

T1003.004
LSA Secrets
GroupOilRig

OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access.

T1003.004
LSA Secrets
GroupKe3chang

Ke3chang has dumped credentials, including by using gsecdump.

T1003.004
LSA Secrets
GroupAPT29

APT29 has used the `reg save` command to extract LSA secrets offline.

T1003.004
LSA Secrets
GroupEmber Bear

Ember Bear has used frameworks such as Impacket to dump LSA secrets for credential capture.

T1003.004
LSA Secrets
GroupThreat Group-3390

Threat Group-3390 actors have used gsecdump to dump credentials. They have also dumped credentials from domain controllers.

T1003.004
LSA Secrets
GroupAPT33

APT33 has used a variety of publicly available tools like LaZagne to gather credentials.

T1003.004
LSA Secrets
MalwareCosmicDuke

CosmicDuke collects LSA secrets.

T1003.004
LSA Secrets
MalwareIceApple

IceApple's Credential Dumper module can dump LSA secrets from registry keys, including: `HKLM\SECURITY\Policy\PolEKList\default`, `HKLM\SECURITY\Policy\Secrets\*\CurrVal`, and `HKLM\SECURITY\Policy\Secrets\*\OldVal`.

T1003.004
LSA Secrets
ToolImpacket

SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information.

T1003.004
LSA Secrets
ToolAADInternals

AADInternals can dump secrets from the Local Security Authority.

T1003.004
LSA Secrets
ToolMimikatz

Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the LSA.

T1003.004
LSA Secrets
Toolgsecdump

gsecdump can dump LSA secrets.

T1003.004
LSA Secrets
ToolLaZagne

LaZagne can perform credential dumping from LSA secrets to obtain account and password information.

T1003.004
LSA Secrets
ToolCrackMapExec

CrackMapExec can dump hashed passwords from LSA secrets for the targeted system.

T1003.004
LSA Secrets
ToolPupy

Pupy can use Lazagne for harvesting credentials.

T1003.005
Cached Domain Credentials
GroupMuddyWater

MuddyWater has performed credential dumping with LaZagne.

T1003.005
Cached Domain Credentials
GroupLeafminer

Leafminer used several tools for retrieving login and password information, including LaZagne.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.