ATT&CK · T1003
OS Credential Dumping
Tactics: credential-access
About
Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password. Credentials can be obtained from OS caches, memory, or structures. Credentials can then be used to perform Lateral Movement and access restricted information. Several of the tools mentioned in associated sub-techniques may be used by both adversaries and professional security testers. Additional custom tools likely exist as well.
Platforms: Linux, macOS, WindowsMITRE ATT&CK ↗
Used by actors
13 known groups
Software
7 malware/tools implement this
CarbanakPinchDukeOnionDukeTrojan.KaraganyHOMEFRYRevenge RATMgBot
Corpus indicators tagged with this technique
405 indicators in the corpus carry T1003.
Showing the top 30 by severity of 405.