Sub-technique of T1003 OS Credential Dumping.View on attack.mitre.org
Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS). After a user logs on, the system generates and stores a variety of credential materials in LSASS process memory. These credential materials can be harvested by an administrative user or SYSTEM and used to conduct Lateral Movement using Use Alternate Authentication Material.
As well as in-memory techniques, the LSASS process memory can be dumped from the target host and analyzed on a local system.
For example, on the target host use procdump:
* procdump -ma lsass.exe lsass_dump
Locally, mimikatz can be run using:
* sekurlsa::Minidump lsassdump.dmp
* sekurlsa::logonPasswords
Built-in Windows tools such as `comsvcs.dll` can also be used:
* rundll32.exe C:\Windows\System32\comsvcs.dll MiniDump PID lsass.dmp full
Similar to Image File Execution Options Injection, the silent process exit mechanism can be abused to create a memory dump of `lsass.exe` through Windows Error Reporting (`WerFault.exe`).
Windows Security Support Provider (SSP) DLLs are loaded into LSASS process at system start. Once loaded into the LSA, SSP DLLs have access to encrypted and plaintext passwords that are stored in Windows, such as any logged-on user's Domain password or smart card PINs. The SSP configuration is stored in two Registry keys: HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Security Packages and HKLM\SYSTEM\CurrentControlSet\Control\Lsa\OSConfig\Security Packages. An adversary may modify these Registry keys to add new SSPs, which will be loaded the next time the system boots, or when the AddSecurityPackage Windows API function is called.
The following SSPs can be used to access credentials:
* Msv: Interactive logons, batch logons, and service logons are done through the MSV authentication package.
* Wdigest: The Digest Authentication protocol is designed for use with Hypertext Transfer Protocol (HTTP) and Simple Authentication Security Layer (SASL) exchanges.
* Kerberos: Preferred for mutual client-server domain authentication in Windows 2000 and later.
* CredSSP: Provides SSO and Network Level Authentication for Remote Desktop Services.
Rules on DetectionCode tagged with T1003.001.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Access LSASS Memory for Dump Creation | TTP | NULL | Sysmon EventID 10 |
| Cisco Secure Firewall - Veeam CVE-2023-27532 Exploitation Activity | TTP | NULL | Cisco Secure Firewall Threat Defense Intrusion Event |
| Create Remote Thread into LSASS | TTP | NULL | Sysmon EventID 8 |
| Creation of lsass Dump with Taskmgr | TTP | NULL | Sysmon EventID 11 |
| Detect Credential Dumping through LSASS access | TTP | NULL | Sysmon EventID 10 |
| Detect Mimikatz Using Loaded Images | TTP | NULL | Sysmon EventID 7 |
| Detect Mimikatz Via PowerShell And EventCode 4703 | TTP | NULL | |
| Dump LSASS via comsvcs DLL | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Dump LSASS via procdump | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Dump LSASS via procdump Rename | Hunting | NULL | Sysmon EventID 1 |
| Unsigned Image Loaded by LSASS | TTP | NULL | Sysmon EventID 7 |
| Windows Credential Dumping LSASS Memory Createdump | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Hunting System Account Targeting Lsass | Hunting | NULL | Sysmon EventID 10 |
| Windows Non-System Account Targeting Lsass | TTP | NULL | Sysmon EventID 10 |
| Windows Possible Credential Dumping | Anomaly | NULL | Sysmon EventID 10 |
| Used by | Procedure example |
|---|---|
| GroupAgrius | Agrius used tools such as Mimikatz to dump LSASS memory to capture credentials in victim environments. |
| GroupAPT1 | APT1 has been known to use credential dumping using Mimikatz. |
| GroupAPT28 | APT28 regularly deploys both publicly available (ex: Mimikatz) and custom password retrieval tools on victims. They have also dumped the LSASS process memory using the MiniDump function. |
| GroupAPT3 | APT3 has used a tool to dump credentials by injecting itself into lsass.exe and triggering with the argument "dig." |
| GroupAPT32 | APT32 used Mimikatz and customized versions of Windows Credential Dumper to harvest credentials. |
| GroupAPT33 | APT33 has used a variety of publicly available tools like LaZagne, Mimikatz, and ProcDump to dump credentials. |
| GroupAPT39 | APT39 has used Mimikatz, Windows Credential Editor and ProcDump to dump credentials. |
| GroupAPT41 | APT41 has used hashdump, Mimikatz, Procdump, and the Windows Credential Editor to dump password hashes from memory and authenticate to other user accounts. |
| Used by | Procedure example |
|---|---|
| MalwareBad Rabbit | Bad Rabbit has used Mimikatz to harvest credentials from the victim's machine. |
| MalwareCobalt Strike | Cobalt Strike can spawn a job to inject into LSASS memory and dump password hashes. |
| MalwareCozyCar | CozyCar has executed Mimikatz to harvest stored credentials from the victim and further victim penetration. |
| MalwareDaserf | Daserf leverages Mimikatz and Windows Credential Editor to steal credentials. |
| MalwareEmotet | Emotet has been observed dropping and executing password grabber modules including Mimikatz. |
| ToolEmpire | Empire contains an implementation of Mimikatz to gather credentials from memory. |
| MalwareGreyEnergy | GreyEnergy has a module for Mimikatz to collect Windows credentials from the victim’s machine. |
| ToolImpacket | SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information. |
| Used by | Procedure example |
|---|---|
| Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used Mimikatz to capture and use legitimate credentials. |
| Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries attempted to dump credentials utilizing LSASS. |
| CampaignC0032 | During the C0032 campaign, TEMP.Veles used Mimikatz and a custom tool, SecHack, to harvest credentials. |
| CampaignCutting Edge | During Cutting Edge, threat actors used Task Manager to dump LSASS memory from Windows devices to disk. |
| CampaignHomeLand Justice | During HomeLand Justice, threat actors dumped LSASS memory on compromised hosts. |
| CampaignOperation Digital Eye | During Operation Digital Eye, threat actors targeted memory from the LSASS process to extract credentials. |
| CampaignOperation Wocao | During Operation Wocao, threat actors used ProcDump to dump credentials from memory. |
| CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors used Mimikatz to dump LSASS memory. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.