ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1003.002×

14 examples

TechniqueUsed byProcedure example
T1003.002
Security Account Manager
GroupGALLIUM

GALLIUM used reg commands to dump specific hives from the Windows Registry, such as the SAM hive, and obtain password hashes.

T1003.002
Security Account Manager
GroupAPT41

APT41 extracted user account data from the Security Account Managerr (SAM), making a copy of this database from the registry using the reg save command or by exploiting volume shadow copies.

T1003.002
Security Account Manager
GroupDragonfly

Dragonfly has dropped and executed SecretsDump to dump password hashes.

T1003.002
Security Account Manager
GroupmenuPass

menuPass has used a modified version of pentesting tools wmiexec.vbs and secretsdump.py to dump credentials.

T1003.002
Security Account Manager
GroupKe3chang

Ke3chang has dumped credentials, including by using gsecdump.

T1003.002
Security Account Manager
GroupAPT29

APT29 has used the `reg save` command to save registry hives.

T1003.002
Security Account Manager
GroupMirrorFace

MirrorFace has used vssadmin to copy registry hives including SAM.

T1003.002
Security Account Manager
GroupEmber Bear

Ember Bear acquires victim credentials by extracting registry hives such as the Security Account Manager through commands such as reg save.

T1003.002
Security Account Manager
GroupAgrius

Agrius dumped the SAM file on victim machines to capture credentials.

T1003.002
Security Account Manager
GroupAPT5

APT5 has copied and exfiltrated the SAM Registry hive from targeted systems.

T1003.002
Security Account Manager
GroupWizard Spider

Wizard Spider has acquired credentials from the SAM/SECURITY registry hives.

T1003.002
Security Account Manager
GroupDaggerfly

Daggerfly used Reg to dump the Security Account Manager (SAM) hive from victim machines for follow-on credential extraction.

T1003.002
Security Account Manager
GroupThreat Group-3390

Threat Group-3390 actors have used gsecdump to dump credentials. They have also dumped credentials from domain controllers.

T1003.002
Security Account Manager
GroupFIN13

FIN13 has extracted the SAM and SYSTEM registry hives using the `reg.exe` binary for obtaining password hashes from a compromised machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.