ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1003×

13 examples

TechniqueUsed byProcedure example
T1003
OS Credential Dumping
GroupEmber Bear

Ember Bear gathers credential material from target systems, such as SSH keys, to facilitate access to victim environments.

T1003
OS Credential Dumping
GroupAPT39

APT39 has used different versions of Mimikatz to obtain credentials.

T1003
OS Credential Dumping
GroupPoseidon Group

Poseidon Group conducts credential dumping on victims, with a focus on obtaining credentials belonging to domain and database servers.

T1003
OS Credential Dumping
GroupMustang Panda

Mustang Panda utilized “Hdump” to dump credentials from memory.

T1003
OS Credential Dumping
GroupTonto Team

Tonto Team has used a variety of credential dumping tools.

T1003
OS Credential Dumping
GroupAPT32

APT32 used GetPassword_x64 to harvest credentials.

T1003
OS Credential Dumping
GroupSuckfly

Suckfly used a signed credential-dumping tool to obtain victim account credentials.

T1003
OS Credential Dumping
GroupBlackByte

BlackByte used tools such as Cobalt Strike and Mimikatz to dump credentials from victim systems.

T1003
OS Credential Dumping
GroupAPT28

APT28 regularly deploys both publicly available (ex: Mimikatz) and custom password retrieval tools on victims.

T1003
OS Credential Dumping
GroupSowbug

Sowbug has used credential dumping tools.

T1003
OS Credential Dumping
GroupStorm-0501

Storm-0501 has used the SecretsDump module within Impacket can perform credential dumping to obtain account and password information.

T1003
OS Credential Dumping
GroupAxiom

Axiom has been known to dump credentials.

T1003
OS Credential Dumping
GroupLeviathan

Leviathan has used publicly available tools to dump password hashes, including HOMEFRY.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.