Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password, from the operating system and software. Credentials can then be used to perform Lateral Movement and access restricted information.
Several of the tools mentioned in associated sub-techniques may be used by both adversaries and professional security testers. Additional custom tools likely exist as well.
View in MITRE ATT&CK®Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name |
---|---|---|---|---|
chronicle | Chronicle | technique_scores | T1003 | OS Credential Dumping |
Technique ID | Technique Name | Number of Mappings |
---|---|---|
T1003.001 | LSASS Memory | 1 |
T1003.003 | NTDS | 1 |