// MITRE ATT&CK
T1003 · OS Credential Dumping
Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password. Credentials can be obtained from OS caches, memory, or structures.(Citation: Brining MimiKatz to Unix) Credentials can then be used to perform [Latera...
¿Cómo detectarlo y mitigarlo?
La detección de OS Credential Dumping parte de la telemetría de tu SIEM/EDR. Escribe una regla de detección con el generador Sigma, analiza logs sospechosos en el analizador de logs y sitúa la técnica en tu cobertura con la matriz ATT&CK.
Sub-técnicas (8)
T1003.001
LSASS Memory T1003.002
Security Account Manager T1003.003
NTDS T1003.004
LSA Secrets T1003.005
Cached Domain Credentials T1003.006
DCSync T1003.007
Proc Filesystem T1003.008
/etc/passwd and /etc/shadow
LSASS Memory T1003.002
Security Account Manager T1003.003
NTDS T1003.004
LSA Secrets T1003.005
Cached Domain Credentials T1003.006
DCSync T1003.007
Proc Filesystem T1003.008
/etc/passwd and /etc/shadow
Técnicas relacionadas
T1557
Adversary-in-the-Middle T1110.001
Password Guessing T1539
Steal Web Session Cookie T1003.002
Security Account Manager T1552.005
Cloud Instance Metadata API T1555.002
Securityd Memory T1110.002
Password Cracking T1555.001
Keychain
Adversary-in-the-Middle T1110.001
Password Guessing T1539
Steal Web Session Cookie T1003.002
Security Account Manager T1552.005
Cloud Instance Metadata API T1555.002
Securityd Memory T1110.002
Password Cracking T1555.001
Keychain
Fuente: MITRE ATT&CK®. ATT&CK es una marca registrada de The MITRE Corporation. Contenido con fines educativos.