Real-world descriptions of how a group, tool or campaign used a technique.
10 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.004 LSA Secrets |
GroupDragonfly | Dragonfly has dropped and executed SecretsDump to dump password hashes. |
| T1003.004 LSA Secrets |
GroupmenuPass | menuPass has used a modified version of pentesting tools wmiexec.vbs and secretsdump.py to dump credentials. |
| T1003.004 LSA Secrets |
GroupMuddyWater | MuddyWater has performed credential dumping with LaZagne. |
| T1003.004 LSA Secrets |
GroupLeafminer | Leafminer used several tools for retrieving login and password information, including LaZagne. |
| T1003.004 LSA Secrets |
GroupOilRig | OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. |
| T1003.004 LSA Secrets |
GroupKe3chang | Ke3chang has dumped credentials, including by using gsecdump. |
| T1003.004 LSA Secrets |
GroupAPT29 | APT29 has used the `reg save` command to extract LSA secrets offline. |
| T1003.004 LSA Secrets |
GroupEmber Bear | Ember Bear has used frameworks such as Impacket to dump LSA secrets for credential capture. |
| T1003.004 LSA Secrets |
GroupThreat Group-3390 | Threat Group-3390 actors have used gsecdump to dump credentials. They have also dumped credentials from domain controllers. |
| T1003.004 LSA Secrets |
GroupAPT33 | APT33 has used a variety of publicly available tools like LaZagne to gather credentials. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.