ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1003.002×

15 examples

TechniqueUsed byProcedure example
T1003.002
Security Account Manager
MalwareCosmicDuke

CosmicDuke collects Windows account hashes.

T1003.002
Security Account Manager
MalwareHOPLIGHT

HOPLIGHT has the capability to harvest credentials and passwords from the SAM database.

T1003.002
Security Account Manager
MalwareRemsec

Remsec can dump the SAM database.

T1003.002
Security Account Manager
MalwareCobalt Strike

Cobalt Strike can recover hashed passwords.

T1003.002
Security Account Manager
MalwareIceApple

IceApple's Credential Dumper module can dump encrypted password hashes from SAM registry keys, including `HKLM\SAM\SAM\Domains\Account\F` and `HKLM\SAM\SAM\Domains\Account\Users\*\V`.

T1003.002
Security Account Manager
MalwareCozyCar

Password stealer and NTLM stealer modules in CozyCar harvest stored credentials from the victim, including credentials used as part of Windows NTLM user authentication.

T1003.002
Security Account Manager
MalwarePOWERTON

POWERTON has the ability to dump password hashes.

T1003.002
Security Account Manager
MalwareMivast

Mivast has the capability to gather NTLM password information.

T1003.002
Security Account Manager
ToolImpacket

SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information.

T1003.002
Security Account Manager
ToolFgdump

Fgdump can dump Windows password hashes.

T1003.002
Security Account Manager
Toolpwdump

pwdump can be used to dump credentials from the SAM.

T1003.002
Security Account Manager
ToolMimikatz

Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the SAM table.

T1003.002
Security Account Manager
Toolgsecdump

gsecdump can dump Windows password hashes from the SAM.

T1003.002
Security Account Manager
ToolCrackMapExec

CrackMapExec can dump usernames and hashed passwords from the SAM.

T1003.002
Security Account Manager
ToolKoadic

Koadic can gather hashed passwords by dumping SAM/SECURITY hive.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.