ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1003.001×

9 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors used Mimikatz to dump LSASS memory.

T1003.001
LSASS Memory
CampaignTriton Safety Instrumented System Attack

In the Triton Safety Instrumented System Attack, TEMP.Veles used Mimikatz.

T1003.001
LSASS Memory
CampaignCutting Edge

During Cutting Edge, threat actors used Task Manager to dump LSASS memory from Windows devices to disk.

T1003.001
LSASS Memory
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors targeted memory from the LSASS process to extract credentials.

T1003.001
LSASS Memory
CampaignHomeLand Justice

During HomeLand Justice, threat actors dumped LSASS memory on compromised hosts.

T1003.001
LSASS Memory
CampaignC0032

During the C0032 campaign, TEMP.Veles used Mimikatz and a custom tool, SecHack, to harvest credentials.

T1003.001
LSASS Memory
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries attempted to dump credentials utilizing LSASS.

T1003.001
LSASS Memory
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team used Mimikatz to capture and use legitimate credentials.

T1003.001
LSASS Memory
CampaignOperation Wocao

During Operation Wocao, threat actors used ProcDump to dump credentials from memory.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.