Sub-technique of T1003 OS Credential Dumping.View on attack.mitre.org
Adversaries with SYSTEM access to a host may attempt to access Local Security Authority (LSA) secrets, which can contain a variety of different credential materials, such as credentials for service accounts. LSA secrets are stored in the registry at HKEY_LOCAL_MACHINE\SECURITY\Policy\Secrets. LSA secrets can also be dumped from memory.
Reg can be used to extract from the Registry. Mimikatz can be used to extract secrets from memory.
Rules on DetectionCode tagged with T1003.004.
| Rule | Level | Log source |
|---|---|---|
| HackTool - Credential Dumping Tools Named Pipe Created | critical | windows / pipe_created |
| Cred Dump Tools Dropped Files | high | windows / file_event |
| Credential Dumping Tools Service Execution - Security | high | windows / NULL |
| Credential Dumping Tools Service Execution - System | high | windows / NULL |
| DPAPI Domain Backup Key Extraction | high | windows / NULL |
| Dumping of Sensitive Hives Via Reg.EXE | high | windows / process_creation |
| HackTool - Mimikatz Execution | high | windows / process_creation |
| Mimikatz Use | high | windows / NULL |
| Possible Impacket SecretDump Remote Activity | high | windows / NULL |
| Possible Impacket SecretDump Remote Activity - Zeek | high | zeek / NULL |
| PUA - Memory Dump Mount Via MemProcFS | high | windows / process_creation |
| DPAPI Domain Master Key Backup Attempt | medium | windows / NULL |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Windows LSA Secrets NoLMhash Registry | TTP | NULL | Sysmon EventID 13 |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupAPT29 | APT29 has used the `reg save` command to extract LSA secrets offline. |
| GroupAPT33 | APT33 has used a variety of publicly available tools like LaZagne to gather credentials. |
| GroupDragonfly | Dragonfly has dropped and executed SecretsDump to dump password hashes. |
| GroupEmber Bear | Ember Bear has used frameworks such as Impacket to dump LSA secrets for credential capture. |
| GroupKe3chang | Ke3chang has dumped credentials, including by using gsecdump. |
| GroupLeafminer | Leafminer used several tools for retrieving login and password information, including LaZagne. |
| GroupmenuPass | menuPass has used a modified version of pentesting tools wmiexec.vbs and secretsdump.py to dump credentials. |
| GroupMuddyWater | MuddyWater has performed credential dumping with LaZagne. |
| Used by | Procedure example |
|---|---|
| ToolAADInternals | AADInternals can dump secrets from the Local Security Authority. |
| MalwareCosmicDuke | CosmicDuke collects LSA secrets. |
| ToolCrackMapExec | CrackMapExec can dump hashed passwords from LSA secrets for the targeted system. |
| Toolgsecdump | gsecdump can dump LSA secrets. |
| MalwareIceApple | IceApple's Credential Dumper module can dump LSA secrets from registry keys, including: `HKLM\SECURITY\Policy\PolEKList\default`, `HKLM\SECURITY\Policy\Secrets\*\CurrVal`, and `HKLM\SECURITY\Policy\Secrets\*\OldVal`. |
| ToolImpacket | SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information. |
| ToolLaZagne | LaZagne can perform credential dumping from LSA secrets to obtain account and password information. |
| ToolMimikatz | Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the LSA. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.