T1003 OS Credential Dumping — ATT&CK Technique
Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password. Credentials can be obtained from OS caches, memory, or structures. Credentials can then be used to perform Lateral Movement and access restricted information. Several of the tools mentioned in associated sub-techniques may be used by both adversaries and professional security testers. Additional custom tools likely exist as well.
Detection coverage (46)
- Potential Exploitation of CVE-2025-5054 or CVE-2025-4598 medium
- Access To Chromium Browsers Sensitive Files By Uncommon Applications low
- Access To Browser Credential Files By Uncommon Applications low
- OpenCanary - MySQL Login Attempt high
- OpenCanary - MSSQL Login Attempt Via SQLAuth high
- OpenCanary - REDIS Action Command Attempt high
- OpenCanary - MSSQL Login Attempt Via Windows Authentication high
- Antivirus Password Dumper Detection critical
- PUA - AWS TruffleHog Execution medium
- Rare Subscription-level Operations In Azure medium
- Linux Keylogging with Pam.d high
- PUA - Memory Dump Mount Via MemProcFS high
- WCE wceaux.dll Access critical
- File Access Of Signal Desktop Sensitive Data medium
- Access To Crypto Currency Wallets By Uncommon Applications medium
- Credential Manager Access By Uncommon Applications medium
- HackTool - Potential Remote Credential Dumping Activity Via CrackMapExec Or Impacket-Secretsdump high
- Potential Credential Dumping Attempt Using New NetworkProvider - CLI high
- Suspicious Loading of Dbgcore/Dbghelp DLLs from Uncommon Location high
- HackTool - Rubeus Execution - ScriptBlock high
- Live Memory Dump Using Powershell high
- Potential Invoke-Mimikatz PowerShell Script high
- Esentutl Gather Credentials medium
- Hacktool Execution - PE Metadata high
- Hacktool Execution - Imphash critical
- HackTool - Rubeus Execution critical
- Microsoft IIS Connection Strings Decryption high
- Microsoft IIS Service Account Password Dumped high
- Potential Credential Dumping Via LSASS Process Clone critical
- Capture Credentials with Rpcping.exe medium
- Interesting Service Enumeration Via Sc.EXE low
- Shadow Copies Creation Using Operating Systems Utilities medium
- Suspicious SYSTEM User Process Creation high
- Loaded Module Enumeration Via Tasklist.EXE medium
- Potentially Suspicious ODBC Driver Registered high
- Potential Credential Dumping Attempt Using New NetworkProvider - REG medium
- Attacker Tools On Endpoint
- Detect Mimikatz With PowerShell Script Block Logging
- Enable WDigest UseLogonCredential Registry
- PetitPotam Suspicious Kerberos TGT Request
- Windows LAPS Password Gathering Via PowerShell Script
- Windows Mimikatz Binary Execution
- Windows Post Exploitation Risk Behavior
- Windows Remote Access Software BRC4 Loaded Dll
- Cisco Secure Firewall - High Priority Intrusion Classification
- Registry Hive File Staged Outside Standard User Profile Path high