Cached Domain Credentials

T1003.005

Sub-technique of T1003 OS Credential Dumping.View on attack.mitre.org

About this technique

Adversaries may attempt to access cached domain credentials used to allow authentication to occur in the event a domain controller is unavailable.

On Windows Vista and newer, the hash format is DCC2 (Domain Cached Credentials version 2) hash, also known as MS-Cache v2 hash. The number of default cached credentials varies and can be altered per system. This hash does not allow pass-the-hash style attacks, and instead requires Password Cracking to recover the plaintext password.

On Linux systems, Active Directory credentials can be accessed through caches maintained by software like System Security Services Daemon (SSSD) or Quest Authentication Services (formerly VAS). Cached credential hashes are typically located at `/var/lib/sss/db/cache.[domain].ldb` for SSSD or `/var/opt/quest/vas/authcache/vas_auth.vdb` for Quest. Adversaries can use utilities, such as `tdbdump`, on these database files to dump the cached hashes and use Password Cracking to obtain the plaintext password.

With SYSTEM or sudo access, the tools/utilities such as Mimikatz, Reg, and secretsdump.py for Windows or Linikatz for Linux can be used to extract the cached credentials.

Note: Cached credentials for Windows Vista are derived using PBKDF2.

Detection rules9

Rules on DetectionCode tagged with T1003.005.

Sigma8

RuleLevelLog source
HackTool - Credential Dumping Tools Named Pipe Createdcriticalwindows / pipe_created
Cred Dump Tools Dropped Fileshighwindows / file_event
Credential Dumping Tools Service Execution - Securityhighwindows / NULL
Credential Dumping Tools Service Execution - Systemhighwindows / NULL
Dumping of Sensitive Hives Via Reg.EXEhighwindows / process_creation
HackTool - Mimikatz Executionhighwindows / process_creation
Potential Reconnaissance For Cached Credentials Via Cmdkey.EXEhighwindows / process_creation
New Generic Credentials Added Via Cmdkey.EXEmediumwindows / process_creation

Splunk1

RuleTypeRiskData source
Windows Cached Domain Credentials Reg QueryAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups4

Software4

Campaigns0

None recorded.

Procedure examples8

Groups4

Used byProcedure example
GroupAPT33

APT33 has used a variety of publicly available tools like LaZagne to gather credentials.

GroupLeafminer

Leafminer used several tools for retrieving login and password information, including LaZagne.

GroupMuddyWater

MuddyWater has performed credential dumping with LaZagne.

GroupOilRig

OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access.

Software4

Used byProcedure example
ToolCachedump

Cachedump can extract cached password hashes from cache entry information.

ToolLaZagne

LaZagne can perform credential dumping from MSCache to obtain account and password information.

MalwareOkrum

Okrum was seen using modified Quarks PwDump to perform credential dumping.

ToolPupy

Pupy can use Lazagne for harvesting credentials.

References4

  1. Brining MimiKatz to Unix Open source
    Tim Wadhwa-Brown. (2018, November). Where 2 worlds collide Bringing Mimikatz et al to UNIX. Retrieved October 13, 2021.
  2. Microsoft - Cached Creds Open source
    Microsoft. (2016, August 21). Cached and Stored Credentials Technical Overview. Retrieved February 21, 2020.
  3. PassLib mscache Open source
    Eli Collins. (2016, November 25). Windows' Domain Cached Credentials v2. Retrieved February 21, 2020.
  4. ired mscache Open source
    Mantvydas Baranauskas. (2019, November 16). Dumping and Cracking mscash - Cached Domain Credentials. Retrieved February 21, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.