T1003 — OS Credential Dumping

provenance: imported · ATT&CK: T1003

T1003: OS Credential Dumping

MITRE ATT&CK® Enterprise technique

Tactics Credential Access
Platforms Linux, macOS, Windows
Permissions required —
Version 2.2

Description

Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password. Credentials can be obtained from OS caches, memory, or structures.(Citation: Brining MimiKatz to Unix) Credentials can then be used to perform Lateral Movement and access restricted information.

Several of the tools mentioned in associated sub-techniques may be used by both adversaries and professional security testers. Additional custom tools likely exist as well.

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1003
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/

See all 697 pages under Attacker techniques (ATT&CK) →

Related pages