Real-world descriptions of how a group, tool or campaign used a technique.
15 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.002 Security Account Manager |
MalwareCosmicDuke | CosmicDuke collects Windows account hashes. |
| T1003.002 Security Account Manager |
MalwareHOPLIGHT | HOPLIGHT has the capability to harvest credentials and passwords from the SAM database. |
| T1003.002 Security Account Manager |
MalwareRemsec | Remsec can dump the SAM database. |
| T1003.002 Security Account Manager |
MalwareCobalt Strike | Cobalt Strike can recover hashed passwords. |
| T1003.002 Security Account Manager |
MalwareIceApple | IceApple's Credential Dumper module can dump encrypted password hashes from SAM registry keys, including `HKLM\SAM\SAM\Domains\Account\F` and `HKLM\SAM\SAM\Domains\Account\Users\*\V`. |
| T1003.002 Security Account Manager |
MalwareCozyCar | Password stealer and NTLM stealer modules in CozyCar harvest stored credentials from the victim, including credentials used as part of Windows NTLM user authentication. |
| T1003.002 Security Account Manager |
MalwarePOWERTON | POWERTON has the ability to dump password hashes. |
| T1003.002 Security Account Manager |
MalwareMivast | Mivast has the capability to gather NTLM password information. |
| T1003.002 Security Account Manager |
ToolImpacket | SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information. |
| T1003.002 Security Account Manager |
ToolFgdump | Fgdump can dump Windows password hashes. |
| T1003.002 Security Account Manager |
Toolpwdump | pwdump can be used to dump credentials from the SAM. |
| T1003.002 Security Account Manager |
ToolMimikatz | Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the SAM table. |
| T1003.002 Security Account Manager |
Toolgsecdump | gsecdump can dump Windows password hashes from the SAM. |
| T1003.002 Security Account Manager |
ToolCrackMapExec | CrackMapExec can dump usernames and hashed passwords from the SAM. |
| T1003.002 Security Account Manager |
ToolKoadic | Koadic can gather hashed passwords by dumping SAM/SECURITY hive. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.