Real-world descriptions of how a group, tool or campaign used a technique.
18 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.003 NTDS |
GroupVolt Typhoon | Volt Typhoon has used ntds.util to create domain controller installation media containing usernames and password hashes. |
| T1003.003 NTDS |
GroupAPT41 | APT41 used ntdsutil to obtain a copy of the victim environment |
| T1003.003 NTDS |
GroupDragonfly | Dragonfly has dropped and executed SecretsDump to dump password hashes. They also obtained ntds.dit from domain controllers. |
| T1003.003 NTDS |
GroupmenuPass | menuPass has used Ntdsutil to dump credentials. |
| T1003.003 NTDS |
GroupHAFNIUM | HAFNIUM has stolen copies of the Active Directory database (NTDS.DIT). |
| T1003.003 NTDS |
GroupFIN6 | FIN6 has used Metasploit’s PsExec NTDSGRAB module to obtain a copy of the victim's Active Directory database. |
| T1003.003 NTDS |
GroupSandworm Team | Sandworm Team has used `ntdsutil.exe` to back up the Active Directory database, likely for credential access. |
| T1003.003 NTDS |
GroupMustang Panda | Mustang Panda has used vssadmin to create a volume shadow copy and retrieve the NTDS.dit file. Mustang Panda has also used |
| T1003.003 NTDS |
GroupScattered Spider | Scattered Spider has extracted the `NTDS.dit` file by creating volume shadow copies of virtual domain controller disks. |
| T1003.003 NTDS |
GroupKe3chang | Ke3chang has used NTDSDump and other password dumping tools to gather credentials. |
| T1003.003 NTDS |
GroupChimera | Chimera has gathered the SYSTEM registry and ntds.dit files from target systems. Chimera specifically has used the NtdsAudit tool to dump the password hashes of domain users via |
| T1003.003 NTDS |
GroupMirrorFace | MirrorFace has dumped NTDS.dit through volume shadow copies. |
| T1003.003 NTDS |
GroupMedusa Group | Medusa Group has accessed the ntds.dit file to engage in credential dumping. |
| T1003.003 NTDS |
GroupAPT28 | APT28 has used the ntdsutil.exe utility to export the Active Directory database for credential access. |
| T1003.003 NTDS |
GroupFox Kitten | Fox Kitten has used Volume Shadow Copy to access credential information from NTDS. |
| T1003.003 NTDS |
GroupLAPSUS$ | LAPSUS$ has used Windows built-in tool `ntdsutil` to extract the Active Directory (AD) database. |
| T1003.003 NTDS |
GroupWizard Spider | Wizard Spider has gained access to credentials via exported copies of the ntds.dit Active Directory database. Wizard Spider has also created a volume shadow copy and used a batch script file to collect NTDS.dit with the use of the Windows utility, ntdsutil. |
| T1003.003 NTDS |
GroupFIN13 | FIN13 has harvested the NTDS.DIT file and leveraged the Impacket tool on the compromised domain controller to locally decrypt it. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.