T1003

OS Credential Dumping

Adversaries may attempt to dump credentials to obtain account login and password information, normally in hashed form.

ATT&CK / Credential Access

Mimikatz is the quintessential tool for dumping credentials from LSASS memory, used by virtually all sophisticated threat actors.

Defense strategies

  • Credential Guard
  • LSASS protection
  • Restrict debug privileges
  • Monitor for credential dumping tools

Detection methods

  • Monitor LSASS access
  • Detect Mimikatz signatures
  • Track debug privilege usage
  • Alert on credential manager access

T1003 on MITRE ATT&CK ↗