LSA Secrets

T1003.004

Sub-technique of T1003 OS Credential Dumping.View on attack.mitre.org

About this technique

Adversaries with SYSTEM access to a host may attempt to access Local Security Authority (LSA) secrets, which can contain a variety of different credential materials, such as credentials for service accounts. LSA secrets are stored in the registry at HKEY_LOCAL_MACHINE\SECURITY\Policy\Secrets. LSA secrets can also be dumped from memory.

Reg can be used to extract from the Registry. Mimikatz can be used to extract secrets from memory.

Detection rules13

Rules on DetectionCode tagged with T1003.004.

Sigma12

Splunk1

RuleTypeRiskData source
Windows LSA Secrets NoLMhash RegistryTTPNULLSysmon EventID 13

Groups10

Software9

Campaigns0

None recorded.

Procedure examples19

Groups10

Used byProcedure example
GroupAPT29

APT29 has used the `reg save` command to extract LSA secrets offline.

GroupAPT33

APT33 has used a variety of publicly available tools like LaZagne to gather credentials.

GroupDragonfly

Dragonfly has dropped and executed SecretsDump to dump password hashes.

GroupEmber Bear

Ember Bear has used frameworks such as Impacket to dump LSA secrets for credential capture.

GroupKe3chang

Ke3chang has dumped credentials, including by using gsecdump.

GroupLeafminer

Leafminer used several tools for retrieving login and password information, including LaZagne.

GroupmenuPass

menuPass has used a modified version of pentesting tools wmiexec.vbs and secretsdump.py to dump credentials.

GroupMuddyWater

MuddyWater has performed credential dumping with LaZagne.

View all 10 groups examples

Software9

Used byProcedure example
ToolAADInternals

AADInternals can dump secrets from the Local Security Authority.

MalwareCosmicDuke

CosmicDuke collects LSA secrets.

ToolCrackMapExec

CrackMapExec can dump hashed passwords from LSA secrets for the targeted system.

Toolgsecdump

gsecdump can dump LSA secrets.

MalwareIceApple

IceApple's Credential Dumper module can dump LSA secrets from registry keys, including: `HKLM\SECURITY\Policy\PolEKList\default`, `HKLM\SECURITY\Policy\Secrets\*\CurrVal`, and `HKLM\SECURITY\Policy\Secrets\*\OldVal`.

ToolImpacket

SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information.

ToolLaZagne

LaZagne can perform credential dumping from LSA secrets to obtain account and password information.

ToolMimikatz

Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the LSA.

View all 9 software examples

References4

  1. Microsoft AD Admin Tier Model Open source
    Microsoft. (2019, February 14). Active Directory administrative tier model. Retrieved February 21, 2020.
  2. Passcape LSA Secrets Open source
    Passcape. (n.d.). Windows LSA secrets. Retrieved February 21, 2020.
  3. Tilbury Windows Credentials Open source
    Chad Tilbury. (2017, August 8). 1Windows Credentials: Attack, Mitigation, Defense. Retrieved February 21, 2020.
  4. ired Dumping LSA Secrets Open source
    Mantvydas Baranauskas. (2019, November 16). Dumping LSA Secrets. Retrieved February 21, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.