ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1003.003×

18 examples

TechniqueUsed byProcedure example
T1003.003
NTDS
GroupVolt Typhoon

Volt Typhoon has used ntds.util to create domain controller installation media containing usernames and password hashes.

T1003.003
NTDS
GroupAPT41

APT41 used ntdsutil to obtain a copy of the victim environment ntds.dit file.

T1003.003
NTDS
GroupDragonfly

Dragonfly has dropped and executed SecretsDump to dump password hashes. They also obtained ntds.dit from domain controllers.

T1003.003
NTDS
GroupmenuPass

menuPass has used Ntdsutil to dump credentials.

T1003.003
NTDS
GroupHAFNIUM

HAFNIUM has stolen copies of the Active Directory database (NTDS.DIT).

T1003.003
NTDS
GroupFIN6

FIN6 has used Metasploit’s PsExec NTDSGRAB module to obtain a copy of the victim's Active Directory database.

T1003.003
NTDS
GroupSandworm Team

Sandworm Team has used `ntdsutil.exe` to back up the Active Directory database, likely for credential access.

T1003.003
NTDS
GroupMustang Panda

Mustang Panda has used vssadmin to create a volume shadow copy and retrieve the NTDS.dit file. Mustang Panda has also used reg save on the SYSTEM file Registry location to help extract the NTDS.dit file.

T1003.003
NTDS
GroupScattered Spider

Scattered Spider has extracted the `NTDS.dit` file by creating volume shadow copies of virtual domain controller disks.

T1003.003
NTDS
GroupKe3chang

Ke3chang has used NTDSDump and other password dumping tools to gather credentials.

T1003.003
NTDS
GroupChimera

Chimera has gathered the SYSTEM registry and ntds.dit files from target systems. Chimera specifically has used the NtdsAudit tool to dump the password hashes of domain users via msadcs.exe "NTDS.dit" -s "SYSTEM" -p RecordedTV_pdmp.txt --users-csv RecordedTV_users.csv and used ntdsutil to copy the Active Directory database.

T1003.003
NTDS
GroupMirrorFace

MirrorFace has dumped NTDS.dit through volume shadow copies.

T1003.003
NTDS
GroupMedusa Group

Medusa Group has accessed the ntds.dit file to engage in credential dumping.

T1003.003
NTDS
GroupAPT28

APT28 has used the ntdsutil.exe utility to export the Active Directory database for credential access.

T1003.003
NTDS
GroupFox Kitten

Fox Kitten has used Volume Shadow Copy to access credential information from NTDS.

T1003.003
NTDS
GroupLAPSUS$

LAPSUS$ has used Windows built-in tool `ntdsutil` to extract the Active Directory (AD) database.

T1003.003
NTDS
GroupWizard Spider

Wizard Spider has gained access to credentials via exported copies of the ntds.dit Active Directory database. Wizard Spider has also created a volume shadow copy and used a batch script file to collect NTDS.dit with the use of the Windows utility, ntdsutil.

T1003.003
NTDS
GroupFIN13

FIN13 has harvested the NTDS.DIT file and leveraged the Impacket tool on the compromised domain controller to locally decrypt it.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.