// MITRE ATT&CK
T1003 · OS Credential Dumping
Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password. Credentials can be obtained from OS caches, memory, or structures.(Citation: Brining MimiKatz to Unix) Credentials can then be used to perform [Latera...
How to detect & mitigate it
Detecting OS Credential Dumping starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.
Sub-techniques (8)
T1003.001
LSASS Memory T1003.002
Security Account Manager T1003.003
NTDS T1003.004
LSA Secrets T1003.005
Cached Domain Credentials T1003.006
DCSync T1003.007
Proc Filesystem T1003.008
/etc/passwd and /etc/shadow
LSASS Memory T1003.002
Security Account Manager T1003.003
NTDS T1003.004
LSA Secrets T1003.005
Cached Domain Credentials T1003.006
DCSync T1003.007
Proc Filesystem T1003.008
/etc/passwd and /etc/shadow
Related techniques
T1557
Adversary-in-the-Middle T1110.001
Password Guessing T1539
Steal Web Session Cookie T1003.002
Security Account Manager T1552.005
Cloud Instance Metadata API T1555.002
Securityd Memory T1110.002
Password Cracking T1555.001
Keychain
Adversary-in-the-Middle T1110.001
Password Guessing T1539
Steal Web Session Cookie T1003.002
Security Account Manager T1552.005
Cloud Instance Metadata API T1555.002
Securityd Memory T1110.002
Password Cracking T1555.001
Keychain
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.