Real-world descriptions of how a group, tool or campaign used a technique.
14 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.002 Security Account Manager |
GroupGALLIUM | GALLIUM used |
| T1003.002 Security Account Manager |
GroupAPT41 | APT41 extracted user account data from the Security Account Managerr (SAM), making a copy of this database from the registry using the |
| T1003.002 Security Account Manager |
GroupDragonfly | Dragonfly has dropped and executed SecretsDump to dump password hashes. |
| T1003.002 Security Account Manager |
GroupmenuPass | menuPass has used a modified version of pentesting tools wmiexec.vbs and secretsdump.py to dump credentials. |
| T1003.002 Security Account Manager |
GroupKe3chang | Ke3chang has dumped credentials, including by using gsecdump. |
| T1003.002 Security Account Manager |
GroupAPT29 | APT29 has used the `reg save` command to save registry hives. |
| T1003.002 Security Account Manager |
GroupMirrorFace | MirrorFace has used vssadmin to copy registry hives including SAM. |
| T1003.002 Security Account Manager |
GroupEmber Bear | Ember Bear acquires victim credentials by extracting registry hives such as the Security Account Manager through commands such as |
| T1003.002 Security Account Manager |
GroupAgrius | Agrius dumped the SAM file on victim machines to capture credentials. |
| T1003.002 Security Account Manager |
GroupAPT5 | APT5 has copied and exfiltrated the SAM Registry hive from targeted systems. |
| T1003.002 Security Account Manager |
GroupWizard Spider | Wizard Spider has acquired credentials from the SAM/SECURITY registry hives. |
| T1003.002 Security Account Manager |
GroupDaggerfly | Daggerfly used Reg to dump the Security Account Manager (SAM) hive from victim machines for follow-on credential extraction. |
| T1003.002 Security Account Manager |
GroupThreat Group-3390 | Threat Group-3390 actors have used gsecdump to dump credentials. They have also dumped credentials from domain controllers. |
| T1003.002 Security Account Manager |
GroupFIN13 | FIN13 has extracted the SAM and SYSTEM registry hives using the `reg.exe` binary for obtaining password hashes from a compromised machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.