Real-world descriptions of how a group, tool or campaign used a technique.
26 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
MalwareBad Rabbit | Bad Rabbit has used Mimikatz to harvest credentials from the victim's machine. |
| T1003.001 LSASS Memory |
MalwareGreyEnergy | GreyEnergy has a module for Mimikatz to collect Windows credentials from the victim’s machine. |
| T1003.001 LSASS Memory |
MalwareEmotet | Emotet has been observed dropping and executing password grabber modules including Mimikatz. |
| T1003.001 LSASS Memory |
MalwareOlympic Destroyer | Olympic Destroyer contains a module that tries to obtain credentials from LSASS, similar to Mimikatz. These credentials are used with PsExec and Windows Management Instrumentation to help the malware propagate itself across a network. |
| T1003.001 LSASS Memory |
MalwareMafalda | Mafalda can dump password hashes from `LSASS.exe`. |
| T1003.001 LSASS Memory |
MalwareOkrum | Okrum was seen using MimikatzLite to perform credential dumping. |
| T1003.001 LSASS Memory |
MalwareNotPetya | NotPetya contains a modified version of Mimikatz to help gather credentials that are later used for lateral movement. |
| T1003.001 LSASS Memory |
MalwarePysa | |
| T1003.001 LSASS Memory |
MalwareCobalt Strike | Cobalt Strike can spawn a job to inject into LSASS memory and dump password hashes. |
| T1003.001 LSASS Memory |
MalwareDaserf | Daserf leverages Mimikatz and Windows Credential Editor to steal credentials. |
| T1003.001 LSASS Memory |
MalwarePoetRAT | PoetRAT used voStro.exe, a compiled pypykatz (Python version of Mimikatz), to steal credentials. |
| T1003.001 LSASS Memory |
MalwareQilin | Qilin can employ an embedded Mimikatz module to dump LSASS memory. |
| T1003.001 LSASS Memory |
MalwareCozyCar | CozyCar has executed Mimikatz to harvest stored credentials from the victim and further victim penetration. |
| T1003.001 LSASS Memory |
MalwareLizar | |
| T1003.001 LSASS Memory |
MalwareNet Crawler | Net Crawler uses credential dumpers such as Mimikatz and Windows Credential Editor to extract cached credentials from Windows systems. |
| T1003.001 LSASS Memory |
ToolSliver | Sliver has a built-in `procdump` command allowing for retrieval of memory from processes such as `lsass.exe` for credential harvesting. |
| T1003.001 LSASS Memory |
ToolSILENTTRINITY | SILENTTRINITY can create a memory dump of LSASS via the `MiniDumpWriteDump Win32` API call. |
| T1003.001 LSASS Memory |
ToolPowerSploit | PowerSploit contains a collection of Exfiltration modules that can harvest credentials using Mimikatz. |
| T1003.001 LSASS Memory |
ToolWindows Credential Editor | Windows Credential Editor can dump credentials. |
| T1003.001 LSASS Memory |
ToolImpacket | SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information. |
| T1003.001 LSASS Memory |
ToolLslsass | Lslsass can dump active logon session password hashes from the lsass process. |
| T1003.001 LSASS Memory |
ToolEmpire | Empire contains an implementation of Mimikatz to gather credentials from memory. |
| T1003.001 LSASS Memory |
ToolPoshC2 | PoshC2 contains an implementation of Mimikatz to gather credentials from memory. |
| T1003.001 LSASS Memory |
ToolMimikatz | Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the LSASS Memory. |
| T1003.001 LSASS Memory |
ToolLaZagne | LaZagne can perform credential dumping from memory to obtain account and password information. |
| T1003.001 LSASS Memory |
ToolPupy | Pupy can execute Lazagne as well as Mimikatz using PowerShell. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.