T1003 — OS Credential Dumping
T1003: OS Credential Dumping
MITRE ATT&CK® Enterprise technique
| Tactics | Credential Access |
| Platforms | Linux, macOS, Windows |
| Permissions required | — |
| Version | 2.2 |
Description
Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password. Credentials can be obtained from OS caches, memory, or structures.(Citation: Brining MimiKatz to Unix) Credentials can then be used to perform Lateral Movement and access restricted information.
Several of the tools mentioned in associated sub-techniques may be used by both adversaries and professional security testers. Additional custom tools likely exist as well.
Detection
(no detection guidance published)
Data sources
- (none listed)
References
- ATT&CK page: https://attack.mitre.org/techniques/T1003
- ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/