Real-world descriptions of how a group, tool or campaign used a technique.
13 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003 OS Credential Dumping |
GroupEmber Bear | Ember Bear gathers credential material from target systems, such as SSH keys, to facilitate access to victim environments. |
| T1003 OS Credential Dumping |
GroupAPT39 | APT39 has used different versions of Mimikatz to obtain credentials. |
| T1003 OS Credential Dumping |
GroupPoseidon Group | Poseidon Group conducts credential dumping on victims, with a focus on obtaining credentials belonging to domain and database servers. |
| T1003 OS Credential Dumping |
GroupMustang Panda | Mustang Panda utilized “Hdump” to dump credentials from memory. |
| T1003 OS Credential Dumping |
GroupTonto Team | Tonto Team has used a variety of credential dumping tools. |
| T1003 OS Credential Dumping |
GroupAPT32 | APT32 used GetPassword_x64 to harvest credentials. |
| T1003 OS Credential Dumping |
GroupSuckfly | Suckfly used a signed credential-dumping tool to obtain victim account credentials. |
| T1003 OS Credential Dumping |
GroupBlackByte | BlackByte used tools such as Cobalt Strike and Mimikatz to dump credentials from victim systems. |
| T1003 OS Credential Dumping |
GroupAPT28 | APT28 regularly deploys both publicly available (ex: Mimikatz) and custom password retrieval tools on victims. |
| T1003 OS Credential Dumping |
GroupSowbug | Sowbug has used credential dumping tools. |
| T1003 OS Credential Dumping |
GroupStorm-0501 | Storm-0501 has used the SecretsDump module within Impacket can perform credential dumping to obtain account and password information. |
| T1003 OS Credential Dumping |
GroupAxiom | Axiom has been known to dump credentials. |
| T1003 OS Credential Dumping |
GroupLeviathan | Leviathan has used publicly available tools to dump password hashes, including HOMEFRY. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.