ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1003.004×

10 examples

TechniqueUsed byProcedure example
T1003.004
LSA Secrets
GroupDragonfly

Dragonfly has dropped and executed SecretsDump to dump password hashes.

T1003.004
LSA Secrets
GroupmenuPass

menuPass has used a modified version of pentesting tools wmiexec.vbs and secretsdump.py to dump credentials.

T1003.004
LSA Secrets
GroupMuddyWater

MuddyWater has performed credential dumping with LaZagne.

T1003.004
LSA Secrets
GroupLeafminer

Leafminer used several tools for retrieving login and password information, including LaZagne.

T1003.004
LSA Secrets
GroupOilRig

OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access.

T1003.004
LSA Secrets
GroupKe3chang

Ke3chang has dumped credentials, including by using gsecdump.

T1003.004
LSA Secrets
GroupAPT29

APT29 has used the `reg save` command to extract LSA secrets offline.

T1003.004
LSA Secrets
GroupEmber Bear

Ember Bear has used frameworks such as Impacket to dump LSA secrets for credential capture.

T1003.004
LSA Secrets
GroupThreat Group-3390

Threat Group-3390 actors have used gsecdump to dump credentials. They have also dumped credentials from domain controllers.

T1003.004
LSA Secrets
GroupAPT33

APT33 has used a variety of publicly available tools like LaZagne to gather credentials.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.