Real-world descriptions of how a group, tool or campaign used a technique.
9 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.004 LSA Secrets |
MalwareCosmicDuke | CosmicDuke collects LSA secrets. |
| T1003.004 LSA Secrets |
MalwareIceApple | IceApple's Credential Dumper module can dump LSA secrets from registry keys, including: `HKLM\SECURITY\Policy\PolEKList\default`, `HKLM\SECURITY\Policy\Secrets\*\CurrVal`, and `HKLM\SECURITY\Policy\Secrets\*\OldVal`. |
| T1003.004 LSA Secrets |
ToolImpacket | SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information. |
| T1003.004 LSA Secrets |
ToolAADInternals | AADInternals can dump secrets from the Local Security Authority. |
| T1003.004 LSA Secrets |
ToolMimikatz | Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the LSA. |
| T1003.004 LSA Secrets |
Toolgsecdump | gsecdump can dump LSA secrets. |
| T1003.004 LSA Secrets |
ToolLaZagne | LaZagne can perform credential dumping from LSA secrets to obtain account and password information. |
| T1003.004 LSA Secrets |
ToolCrackMapExec | CrackMapExec can dump hashed passwords from LSA secrets for the targeted system. |
| T1003.004 LSA Secrets |
ToolPupy | Pupy can use Lazagne for harvesting credentials. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.