ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1003.004×

9 examples

TechniqueUsed byProcedure example
T1003.004
LSA Secrets
MalwareCosmicDuke

CosmicDuke collects LSA secrets.

T1003.004
LSA Secrets
MalwareIceApple

IceApple's Credential Dumper module can dump LSA secrets from registry keys, including: `HKLM\SECURITY\Policy\PolEKList\default`, `HKLM\SECURITY\Policy\Secrets\*\CurrVal`, and `HKLM\SECURITY\Policy\Secrets\*\OldVal`.

T1003.004
LSA Secrets
ToolImpacket

SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information.

T1003.004
LSA Secrets
ToolAADInternals

AADInternals can dump secrets from the Local Security Authority.

T1003.004
LSA Secrets
ToolMimikatz

Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the LSA.

T1003.004
LSA Secrets
Toolgsecdump

gsecdump can dump LSA secrets.

T1003.004
LSA Secrets
ToolLaZagne

LaZagne can perform credential dumping from LSA secrets to obtain account and password information.

T1003.004
LSA Secrets
ToolCrackMapExec

CrackMapExec can dump hashed passwords from LSA secrets for the targeted system.

T1003.004
LSA Secrets
ToolPupy

Pupy can use Lazagne for harvesting credentials.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.