Sub-technique of T1003 OS Credential Dumping.View on attack.mitre.org
Adversaries may attempt to access cached domain credentials used to allow authentication to occur in the event a domain controller is unavailable.
On Windows Vista and newer, the hash format is DCC2 (Domain Cached Credentials version 2) hash, also known as MS-Cache v2 hash. The number of default cached credentials varies and can be altered per system. This hash does not allow pass-the-hash style attacks, and instead requires Password Cracking to recover the plaintext password.
On Linux systems, Active Directory credentials can be accessed through caches maintained by software like System Security Services Daemon (SSSD) or Quest Authentication Services (formerly VAS). Cached credential hashes are typically located at `/var/lib/sss/db/cache.[domain].ldb` for SSSD or `/var/opt/quest/vas/authcache/vas_auth.vdb` for Quest. Adversaries can use utilities, such as `tdbdump`, on these database files to dump the cached hashes and use Password Cracking to obtain the plaintext password.
With SYSTEM or sudo access, the tools/utilities such as Mimikatz, Reg, and secretsdump.py for Windows or Linikatz for Linux can be used to extract the cached credentials.
Note: Cached credentials for Windows Vista are derived using PBKDF2.
Rules on DetectionCode tagged with T1003.005.
| Rule | Level | Log source |
|---|---|---|
| HackTool - Credential Dumping Tools Named Pipe Created | critical | windows / pipe_created |
| Cred Dump Tools Dropped Files | high | windows / file_event |
| Credential Dumping Tools Service Execution - Security | high | windows / NULL |
| Credential Dumping Tools Service Execution - System | high | windows / NULL |
| Dumping of Sensitive Hives Via Reg.EXE | high | windows / process_creation |
| HackTool - Mimikatz Execution | high | windows / process_creation |
| Potential Reconnaissance For Cached Credentials Via Cmdkey.EXE | high | windows / process_creation |
| New Generic Credentials Added Via Cmdkey.EXE | medium | windows / process_creation |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Windows Cached Domain Credentials Reg Query | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupAPT33 | APT33 has used a variety of publicly available tools like LaZagne to gather credentials. |
| GroupLeafminer | Leafminer used several tools for retrieving login and password information, including LaZagne. |
| GroupMuddyWater | MuddyWater has performed credential dumping with LaZagne. |
| GroupOilRig | OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. |
| Used by | Procedure example |
|---|---|
| ToolCachedump | Cachedump can extract cached password hashes from cache entry information. |
| ToolLaZagne | LaZagne can perform credential dumping from MSCache to obtain account and password information. |
| MalwareOkrum | Okrum was seen using modified Quarks PwDump to perform credential dumping. |
| ToolPupy | Pupy can use Lazagne for harvesting credentials. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.