Real-world descriptions of how a group, tool or campaign used a technique.
9 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors used Mimikatz to dump LSASS memory. |
| T1003.001 LSASS Memory |
CampaignTriton Safety Instrumented System Attack | In the Triton Safety Instrumented System Attack, TEMP.Veles used Mimikatz. |
| T1003.001 LSASS Memory |
CampaignCutting Edge | During Cutting Edge, threat actors used Task Manager to dump LSASS memory from Windows devices to disk. |
| T1003.001 LSASS Memory |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors targeted memory from the LSASS process to extract credentials. |
| T1003.001 LSASS Memory |
CampaignHomeLand Justice | During HomeLand Justice, threat actors dumped LSASS memory on compromised hosts. |
| T1003.001 LSASS Memory |
CampaignC0032 | During the C0032 campaign, TEMP.Veles used Mimikatz and a custom tool, SecHack, to harvest credentials. |
| T1003.001 LSASS Memory |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries attempted to dump credentials utilizing LSASS. |
| T1003.001 LSASS Memory |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used Mimikatz to capture and use legitimate credentials. |
| T1003.001 LSASS Memory |
CampaignOperation Wocao | During Operation Wocao, threat actors used ProcDump to dump credentials from memory. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.