OS Credential Dumping

T1003

Technique with 8 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password. Credentials can be obtained from OS caches, memory, or structures. Credentials can then be used to perform Lateral Movement and access restricted information.

Several of the tools mentioned in associated sub-techniques may be used by both adversaries and professional security testers. Additional custom tools likely exist as well.

Detection rules191

Rules on DetectionCode tagged with T1003 or one of its sub-techniques.

Sigma140

RuleLevelLog sourceTechnique
Antivirus - Password Dumper SignaturecriticalNULL / antivirusT1003 T1003.001 T1003.002
HackTool - Credential Dumping Tools Named Pipe Createdcriticalwindows / pipe_createdT1003.001 T1003.002 T1003.004 T1003.005
HackTool - Dumpert Process Dumper Default Filecriticalwindows / file_eventT1003.001
HackTool - Dumpert Process Dumper Executioncriticalwindows / process_creationT1003.001
HackTool - Inveigh Executioncriticalwindows / process_creationT1003.001
HackTool - QuarksPwDump Dump Filecriticalwindows / file_eventT1003.002
HackTool - Rubeus Executioncriticalwindows / process_creationT1003
HackTool - SafetyKatz Executioncriticalwindows / process_creationT1003.001
HackTool - Windows Credential Editor (WCE) Executioncriticalwindows / process_creationT1003.001
Hacktool Execution - Imphashcriticalwindows / process_creationT1003
Potential Credential Dumping Via LSASS Process Clonecriticalwindows / process_creationT1003 T1003.001
Potential Credential Dumping Via LSASS SilentProcessExit Techniquecriticalwindows / registry_eventT1003.001
WCE wceaux.dll Accesscriticalwindows / NULLT1003
Windows Credential Editor Registrycriticalwindows / registry_eventT1003.001
Copying Sensitive Files with Credential Datahighwindows / process_creationT1003.002 T1003.003

Splunk51

RuleTypeRiskData sourceTechnique
Access LSASS Memory for Dump CreationTTPNULLSysmon EventID 10T1003.001
Attacker Tools On EndpointTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow DataT1003
Attempted Credential Dump From Registry via Reg exeTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1003.002
Azure AD Privileged Authentication Administrator Role AssignedTTPNULLAzure Active Directory Add member to roleT1003.002
Azure AD Privileged Graph API Permission AssignedTTPNULLAzure Active Directory Update applicationT1003.002
Cisco Secure Firewall - High Priority Intrusion ClassificationTTPNULLCisco Secure Firewall Threat Defense Intrusion EventT1003
Cisco Secure Firewall - Veeam CVE-2023-27532 Exploitation ActivityTTPNULLCisco Secure Firewall Threat Defense Intrusion EventT1003.001
Create Remote Thread into LSASSTTPNULLSysmon EventID 8T1003.001
Creation of lsass Dump with TaskmgrTTPNULLSysmon EventID 11T1003.001
Creation of Shadow CopyTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1003.003
Creation of Shadow Copy with wmic and powershellTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1003.003
Credential Dumping via Copy Command from Shadow CopyTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1003.003
Credential Dumping via Symlink to Shadow CopyTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1003.003
Detect Copy of ShadowCopy with Script Block LoggingTTPNULLPowershell Script Block Logging 4104T1003.002
Detect Credential Dumping through LSASS accessTTPNULLSysmon EventID 10T1003.001

Sub-techniques8

IDNameExamples
T1003.001LSASS Memory79
T1003.002Security Account Manager36
T1003.003NTDS26
T1003.004LSA Secrets19
T1003.005Cached Domain Credentials8
T1003.006DCSync8
T1003.007Proc Filesystem5
T1003.008/etc/passwd and /etc/shadow2

Groups13

Software7

Campaigns0

None recorded.

Procedure examples20

Groups13

Used byProcedure example
GroupAPT28

APT28 regularly deploys both publicly available (ex: Mimikatz) and custom password retrieval tools on victims.

GroupAPT32

APT32 used GetPassword_x64 to harvest credentials.

GroupAPT39

APT39 has used different versions of Mimikatz to obtain credentials.

GroupAxiom

Axiom has been known to dump credentials.

GroupBlackByte

BlackByte used tools such as Cobalt Strike and Mimikatz to dump credentials from victim systems.

GroupEmber Bear

Ember Bear gathers credential material from target systems, such as SSH keys, to facilitate access to victim environments.

GroupLeviathan

Leviathan has used publicly available tools to dump password hashes, including HOMEFRY.

GroupMustang Panda

Mustang Panda utilized “Hdump” to dump credentials from memory.

View all 13 groups examples

Software7

Used byProcedure example
MalwareCarbanak

Carbanak obtains Windows logon password details.

MalwareHOMEFRY

HOMEFRY can perform credential dumping.

MalwareMgBot

MgBot includes modules for dumping and capturing credentials from process memory.

MalwareOnionDuke

OnionDuke steals credentials from its victims.

MalwarePinchDuke

PinchDuke steals credentials from compromised hosts. PinchDuke's credential stealing functionality is believed to be based on the source code of the Pinch credential stealing malware (also known as LdPinch). Credentials targeted by PinchDuke include ones associated many sources such as WinInet Credential Cache, and Lightweight Directory Access Protocol (LDAP).

MalwareRevenge RAT

Revenge RAT has a plugin for credential harvesting.

MalwareTrojan.Karagany

Trojan.Karagany can dump passwords and save them into \ProgramData\Mail\MailAg\pwds.txt.

References1

  1. Brining MimiKatz to Unix Open source
    Tim Wadhwa-Brown. (2018, November). Where 2 worlds collide Bringing Mimikatz et al to UNIX. Retrieved October 13, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.