FORENSIA

ATT&CK · T1003.004 · sub-technique

LSA Secrets

Tactics: credential-access

About

Adversaries with SYSTEM access to a host may attempt to access Local Security Authority (LSA) secrets, which can contain a variety of different credential materials, such as credentials for service accounts. LSA secrets are stored in the registry at <code>HKEY_LOCAL_MACHINE\SECURITY\Policy\Secrets</code>. LSA secrets can also be dumped from memory. Reg can be used to extract from the Registry. Mimikatz can be used to extract secrets from memory.

Used by actors

10 known groups

Software

9 malware/tools implement this

MimikatzgsecdumpCosmicDukePupyLaZagneImpacketCrackMapExecAADInternalsIceApple

Corpus indicators tagged with this technique

4 indicators in the corpus carry T1003.004.