ATT&CK · T1003.004 · sub-technique
LSA Secrets
Tactics: credential-access
About
Adversaries with SYSTEM access to a host may attempt to access Local Security Authority (LSA) secrets, which can contain a variety of different credential materials, such as credentials for service accounts. LSA secrets are stored in the registry at <code>HKEY_LOCAL_MACHINE\SECURITY\Policy\Secrets</code>. LSA secrets can also be dumped from memory. Reg can be used to extract from the Registry. Mimikatz can be used to extract secrets from memory.
Used by actors
10 known groups
Software
9 malware/tools implement this
MimikatzgsecdumpCosmicDukePupyLaZagneImpacketCrackMapExecAADInternalsIceApple
Corpus indicators tagged with this technique
4 indicators in the corpus carry T1003.004.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| 0f57a2bb4c0696170b73e2d35f17c5a6f2f910d7 | sha1 | — | 78 | 1 |
| 843d2017c4ded1dbb694dd4bf20bcd9e92af92f6 | sha1 | — | 78 | 1 |
| a9336884e006503bc821f3f0d36f141f | md5 | — | 76 | 1 |
| d0bba7c040ecffd8cc31a62330a144eb | md5 | — | 76 | 1 |