MITRE ATT&CK Tactic(s): Credential Access
Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password, from the operating system and software. Credentials can then be used to perform [Lateral Movement](https://attack.mitre.org/tactics/TA0008) and access restricted information.Several of the tools mentioned in associated sub-techniques may be used by both adversaries and professional security testers. Additional custom tools likely exist as well.
Last accessed: May 23, 2022
Total ATT&CK-mapped resources: 2328
ATT&CK-mapped resources for this (sub)technique: 26
Resources mapped to this (sub)technique can be viewed on this page (see also the ATT&CK to D3FEND Mapper tool):
- Decoy User Credential
- Decoy File
- File Analysis
- Credential Compromise Scope Analysis
- User Geolocation Logon Pattern Analysis
- Remote Terminal Session Detection
- Connection Attempt Analysis
- Network Traffic Community Deviation
- Protocol Metadata Anomaly Detection
- Client-server Payload Profiling
- Administrative Network Activity Analysis
- Per Host Download-Upload Ratio Analysis
- Process Self-Modification Detection
- Process Spawn Analysis
- Authentication Cache Invalidation
- Process Termination
- Software Update
- Local File Permissions
- Hardware-based Process Isolation
- Credential Transmission Scoping
- Outbound Traffic Filtering
- Inbound Traffic Filtering
- Process Lineage Analysis
- Service Binary Verification
- System File Analysis
- Mandatory Access Control
Last accessed: August 09, 2022
Total ATT&CK-mapped rules: 641
ATT&CK-mapped resources for this (sub)technique: 9
Resources mapped to this (sub)technique can be located in the following files within the repository's rules folder:
- Kerberos Cached Credentials Dumping)**
- Potential Credential Access via Trusted Developer Utility)**
- Microsoft IIS Service Account Password Dumped)**
- Microsoft IIS Connection Strings Decryption)**
- Mimikatz Memssp Log File Detected)**
- PowerShell Kerberos Ticket Request)**
- Searching for Saved Credentials via VaultCmd)**
- Symbolic Link to Shadow Copy Created)**
Last accessed: August 09, 2022
Total ATT&CK-mapped rules: 450
ATT&CK-mapped resources for this (sub)technique: 7
Resources mapped to this (sub)technique can be located in the following files within the repository's Detections folder:
- ASimFileEvent / Dev-0228 File Path Hashes November 2021 (ASIM Version)
- AzureActivity / Rare subscription-level operations in Azure
- AzureDiagnostics / Mass secret retrieval from Azure Key Vault
- AzureDiagnostics / Azure Key Vault access TimeSeries anomaly
- MultipleDataSources / Dev-0228 File Path Hashes November 2021
- SecurityEvent / Non Domain Controller Active Directory Replication
- SecurityEvent / WDigest downgrade attack
Last accessed: August 09, 2022
Total ATT&CK-mapped rules: 2578
ATT&CK-mapped resources for this (sub)technique: 15
Resources mapped to this (sub)technique can be located in the following files within the repository's rules folder:
- application / antivirus / Antivirus Password Dumper Detection
- cloud / azure / Rare Subscription-level Operations In Azure
- linux / auditd / Linux Keylogging with Pam.d
- windows / builtin / security / WCE wceaux.dll Access
- windows / builtin / security / Malicious Service Installations
- windows / file_access / Browser Credential Store Access
- windows / file_event / Mimikatz MemSSP Default Log File Creation
- windows / image_load / Mimikatz In-Memory
- windows / powershell / powershell_script / Live Memory Dump Using Powershell
- windows / process_creation / Rubeus Hack Tool
- windows / process_creation / Shadow Copies Creation Using Operating Systems Utilities
- windows / process_creation / Esentutl Gather Credentials
- windows / process_creation / Suspicious LSASS Process Clone
- windows / process_creation / Suspicious Reg Add Open Command
- windows / process_creation / Capture Credentials with Rpcping.exe
Last accessed: August 09, 2022
Total ATT&CK-mapped rules: 1624
ATT&CK-mapped resources for this (sub)technique: 31
Resources mapped to this (sub)technique can be located in the following files within the repository's detections folder:
- deprecated / Credential ExtractionFGDump and CacheDump
- endpoint / Access LSASS Memory for Dump Creation
- endpoint / Attacker Tools On Endpoint
- endpoint / Attempted Credential Dump From Registry via Reg exe
- endpoint / Create Remote Thread into LSASS
- endpoint / Creation of lsass Dump with Taskmgr
- endpoint / Creation of Shadow Copy
- endpoint / Creation of Shadow Copy with wmic and powershell
- endpoint / Credential Dumping via Copy Command from Shadow Copy
- endpoint / Credential Dumping via Symlink to Shadow Copy
- endpoint / Detect Copy of ShadowCopy with Script Block Logging
- endpoint / Detect Credential Dumping through LSASS access
- endpoint / Detect Mimikatz Using Loaded Images
- endpoint / Detect Mimikatz With PowerShell Script Block Logging
- endpoint / Dump LSASS via comsvcs DLL
- endpoint / Dump LSASS via procdump
- endpoint / Enable WDigest UseLogonCredential Registry
- endpoint / Esentutl SAM Copy
- endpoint / Excel Spawning PowerShell
- endpoint / Excel Spawning Windows Script Host
- endpoint / Extraction of Registry Hives
- endpoint / Linux Possible Access To Credential Files
- endpoint / Ntdsutil Export NTDS
- endpoint / PetitPotam Suspicious Kerberos TGT Request
- endpoint / SAM Database File Access Attempt
- endpoint / SecretDumps Offline NTDS Dumping Tool
- endpoint / Attempted Credential Dump From Registry via Reg exe
- endpoint / Windows Rundll32 Comsvcs Memory Dump
- endpoint / Windows Hunting System Account Targeting Lsass
- endpoint / Windows Non-System Account Targeting Lsass
- endpoint / Windows Possible Credential Dumping
Last accessed: August 10, 2022
Total ATT&CK-mapped tests: 1341
ATT&CK-mapped resources for this (sub)technique: 3
The following unit tests mapped to this (sub)technique can be located in the file here:
- Gsecdump
- Credential Dumping with NPPSpy
- Dump svchost.exe to gather RDP credentials