ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1003.001×

26 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
MalwareBad Rabbit

Bad Rabbit has used Mimikatz to harvest credentials from the victim's machine.

T1003.001
LSASS Memory
MalwareGreyEnergy

GreyEnergy has a module for Mimikatz to collect Windows credentials from the victim’s machine.

T1003.001
LSASS Memory
MalwareEmotet

Emotet has been observed dropping and executing password grabber modules including Mimikatz.

T1003.001
LSASS Memory
MalwareOlympic Destroyer

Olympic Destroyer contains a module that tries to obtain credentials from LSASS, similar to Mimikatz. These credentials are used with PsExec and Windows Management Instrumentation to help the malware propagate itself across a network.

T1003.001
LSASS Memory
MalwareMafalda

Mafalda can dump password hashes from `LSASS.exe`.

T1003.001
LSASS Memory
MalwareOkrum

Okrum was seen using MimikatzLite to perform credential dumping.

T1003.001
LSASS Memory
MalwareNotPetya

NotPetya contains a modified version of Mimikatz to help gather credentials that are later used for lateral movement.

T1003.001
LSASS Memory
MalwarePysa

Pysa can perform OS credential dumping using Mimikatz.

T1003.001
LSASS Memory
MalwareCobalt Strike

Cobalt Strike can spawn a job to inject into LSASS memory and dump password hashes.

T1003.001
LSASS Memory
MalwareDaserf

Daserf leverages Mimikatz and Windows Credential Editor to steal credentials.

T1003.001
LSASS Memory
MalwarePoetRAT

PoetRAT used voStro.exe, a compiled pypykatz (Python version of Mimikatz), to steal credentials.

T1003.001
LSASS Memory
MalwareQilin

Qilin can employ an embedded Mimikatz module to dump LSASS memory.

T1003.001
LSASS Memory
MalwareCozyCar

CozyCar has executed Mimikatz to harvest stored credentials from the victim and further victim penetration.

T1003.001
LSASS Memory
MalwareLizar

Lizar can run Mimikatz to harvest credentials.

T1003.001
LSASS Memory
MalwareNet Crawler

Net Crawler uses credential dumpers such as Mimikatz and Windows Credential Editor to extract cached credentials from Windows systems.

T1003.001
LSASS Memory
ToolSliver

Sliver has a built-in `procdump` command allowing for retrieval of memory from processes such as `lsass.exe` for credential harvesting.

T1003.001
LSASS Memory
ToolSILENTTRINITY

SILENTTRINITY can create a memory dump of LSASS via the `MiniDumpWriteDump Win32` API call.

T1003.001
LSASS Memory
ToolPowerSploit

PowerSploit contains a collection of Exfiltration modules that can harvest credentials using Mimikatz.

T1003.001
LSASS Memory
ToolWindows Credential Editor

Windows Credential Editor can dump credentials.

T1003.001
LSASS Memory
ToolImpacket

SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information.

T1003.001
LSASS Memory
ToolLslsass

Lslsass can dump active logon session password hashes from the lsass process.

T1003.001
LSASS Memory
ToolEmpire

Empire contains an implementation of Mimikatz to gather credentials from memory.

T1003.001
LSASS Memory
ToolPoshC2

PoshC2 contains an implementation of Mimikatz to gather credentials from memory.

T1003.001
LSASS Memory
ToolMimikatz

Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the LSASS Memory.

T1003.001
LSASS Memory
ToolLaZagne

LaZagne can perform credential dumping from memory to obtain account and password information.

T1003.001
LSASS Memory
ToolPupy

Pupy can execute Lazagne as well as Mimikatz using PowerShell.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.