Technique with 8 sub-techniques.View on attack.mitre.org
Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password. Credentials can be obtained from OS caches, memory, or structures. Credentials can then be used to perform Lateral Movement and access restricted information.
Several of the tools mentioned in associated sub-techniques may be used by both adversaries and professional security testers. Additional custom tools likely exist as well.
Rules on DetectionCode tagged with T1003 or one of its sub-techniques.
| Rule | Type | Risk | Data source | Technique |
|---|---|---|---|---|
| Access LSASS Memory for Dump Creation | TTP | NULL | Sysmon EventID 10 | T1003.001 |
| Attacker Tools On Endpoint | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow Data | T1003 |
| Attempted Credential Dump From Registry via Reg exe | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1003.002 |
| Azure AD Privileged Authentication Administrator Role Assigned | TTP | NULL | Azure Active Directory Add member to role | T1003.002 |
| Azure AD Privileged Graph API Permission Assigned | TTP | NULL | Azure Active Directory Update application | T1003.002 |
| Cisco Secure Firewall - High Priority Intrusion Classification | TTP | NULL | Cisco Secure Firewall Threat Defense Intrusion Event | T1003 |
| Cisco Secure Firewall - Veeam CVE-2023-27532 Exploitation Activity | TTP | NULL | Cisco Secure Firewall Threat Defense Intrusion Event | T1003.001 |
| Create Remote Thread into LSASS | TTP | NULL | Sysmon EventID 8 | T1003.001 |
| Creation of lsass Dump with Taskmgr | TTP | NULL | Sysmon EventID 11 | T1003.001 |
| Creation of Shadow Copy | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1003.003 |
| Creation of Shadow Copy with wmic and powershell | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1003.003 |
| Credential Dumping via Copy Command from Shadow Copy | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1003.003 |
| Credential Dumping via Symlink to Shadow Copy | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1003.003 |
| Detect Copy of ShadowCopy with Script Block Logging | TTP | NULL | Powershell Script Block Logging 4104 | T1003.002 |
| Detect Credential Dumping through LSASS access | TTP | NULL | Sysmon EventID 10 | T1003.001 |
| Detect Mimikatz Using Loaded Images | TTP | NULL | Sysmon EventID 7 | T1003.001 |
| Detect Mimikatz Via PowerShell And EventCode 4703 | TTP | NULL | T1003.001 | |
| Detect Mimikatz With PowerShell Script Block Logging | TTP | NULL | Powershell Script Block Logging 4104 | T1003 |
| Dump LSASS via comsvcs DLL | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1003.001 |
| Dump LSASS via procdump | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1003.001 |
| Dump LSASS via procdump Rename | Hunting | NULL | Sysmon EventID 1 | T1003.001 |
| Enable WDigest UseLogonCredential Registry | TTP | NULL | Sysmon EventID 13 | T1003 |
| Esentutl SAM Copy | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1003.002 |
| ESXi Sensitive Files Accessed | TTP | NULL | VMWare ESXi Syslog | T1003.008 |
| Excel Spawning PowerShell | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1003.002 |
| Excel Spawning Windows Script Host | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1003.002 |
| Extraction of Registry Hives | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1003.002 |
| Linux Auditd Possible Access To Credential Files | Anomaly | NULL | Linux Auditd Proctitle | T1003.008 |
| Linux Possible Access To Credential Files | Anomaly | NULL | Sysmon for Linux EventID 1 | T1003.008 |
| Ntdsutil Export NTDS | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1003.003 |
| O365 Privileged Graph API Permission Assigned | TTP | NULL | O365 Update application. | T1003.002 |
| PetitPotam Suspicious Kerberos TGT Request | TTP | NULL | Windows Event Log Security 4768 | T1003 |
| PowerShell 4104 Hunting | Hunting | NULL | Powershell Script Block Logging 4104 | T1003 |
| SAM Database File Access Attempt | Hunting | NULL | Windows Event Log Security 4663 | T1003.002 |
| SecretDumps Offline NTDS Dumping Tool | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1003.003 |
| Unsigned Image Loaded by LSASS | TTP | NULL | Sysmon EventID 7 | T1003.001 |
| Windows AD Replication Request Initiated by User Account | TTP | NULL | Windows Event Log Security 4662, Windows Event Log Security 4624 | T1003.006 |
| Windows AD Replication Request Initiated from Unsanctioned Location | TTP | NULL | Windows Event Log Security 4662, Windows Event Log Security 4624 | T1003.006 |
| Windows AD Replication Service Traffic | TTP | NULL | T1003.006 | |
| Windows Cached Domain Credentials Reg Query | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1003.005 |
| Windows Credential Dumping LSASS Memory Createdump | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1003.001 |
| Windows Hunting System Account Targeting Lsass | Hunting | NULL | Sysmon EventID 10 | T1003.001 |
| Windows LAPS Password Gathering Via PowerShell Script | Anomaly | NULL | Powershell Script Block Logging 4104 | T1003 |
| Windows LSA Secrets NoLMhash Registry | TTP | NULL | Sysmon EventID 13 | T1003.004 |
| Windows Mimikatz Binary Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1003 |
| Windows Non-System Account Targeting Lsass | TTP | NULL | Sysmon EventID 10 | T1003.001 |
| Windows Possible Credential Dumping | Anomaly | NULL | Sysmon EventID 10 | T1003.001 |
| Windows Post Exploitation Risk Behavior | Correlation | NULL | T1003 | |
| Windows Rapid Authentication On Multiple Hosts | TTP | NULL | Windows Event Log Security 4624 | T1003.002 |
| Windows Remote Access Software BRC4 Loaded Dll | Anomaly | NULL | Sysmon EventID 7 | T1003 |
| Windows Sensitive Registry Hive Dump Via CommandLine | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1003.002 |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupAPT28 | APT28 regularly deploys both publicly available (ex: Mimikatz) and custom password retrieval tools on victims. |
| GroupAPT32 | APT32 used GetPassword_x64 to harvest credentials. |
| GroupAPT39 | APT39 has used different versions of Mimikatz to obtain credentials. |
| GroupAxiom | Axiom has been known to dump credentials. |
| GroupBlackByte | BlackByte used tools such as Cobalt Strike and Mimikatz to dump credentials from victim systems. |
| GroupEmber Bear | Ember Bear gathers credential material from target systems, such as SSH keys, to facilitate access to victim environments. |
| GroupLeviathan | Leviathan has used publicly available tools to dump password hashes, including HOMEFRY. |
| GroupMustang Panda | Mustang Panda utilized “Hdump” to dump credentials from memory. |
| Used by | Procedure example |
|---|---|
| MalwareCarbanak | Carbanak obtains Windows logon password details. |
| MalwareHOMEFRY | HOMEFRY can perform credential dumping. |
| MalwareMgBot | MgBot includes modules for dumping and capturing credentials from process memory. |
| MalwareOnionDuke | OnionDuke steals credentials from its victims. |
| MalwarePinchDuke | PinchDuke steals credentials from compromised hosts. PinchDuke's credential stealing functionality is believed to be based on the source code of the Pinch credential stealing malware (also known as LdPinch). Credentials targeted by PinchDuke include ones associated many sources such as WinInet Credential Cache, and Lightweight Directory Access Protocol (LDAP). |
| MalwareRevenge RAT | Revenge RAT has a plugin for credential harvesting. |
| MalwareTrojan.Karagany | Trojan.Karagany can dump passwords and save them into |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.