Credential Dumping

https://attack.mitre.org/techniques/T1003/

ATT&CK ID: T1003arrow-up-right

Description

Adversaries could attempt to extract credentials and account hashes from various areas of the Operating System. Clear-text passwords and hashes can be used by adversaries to perform Lateral Movementarrow-up-right in the environment.

Sub Techniques

T1003.001: LSASS Memory

LSASS Memorychevron-right

T1003.002: Security Account Manager (SAM)

Security Account Manager (SAM)chevron-right

T1003.003: NTDS

NTDSchevron-right

T1003.004: LSA Secrets

LSA Secretschevron-right

T1003.005: Cached Domain Credentials

Cached Domain Credentialschevron-right

T1003.006: DCSync

DCSyncchevron-right

Last updated