T1003.004 — LSA Secrets
T1003.004: LSA Secrets
MITRE ATT&CK® Enterprise technique
| Tactics | Credential Access |
| Platforms | Windows |
| Permissions required | — |
| Version | 1.1 |
| Parent technique | T1003 |
Description
Adversaries with SYSTEM access to a host may attempt to access Local Security Authority (LSA) secrets, which can contain a variety of different credential materials, such as credentials for service accounts.(Citation: Passcape LSA Secrets)(Citation: Microsoft AD Admin Tier Model)(Citation: Tilbury Windows Credentials) LSA secrets are stored in the registry at <code>HKEY_LOCAL_MACHINE\SECURITY\Policy\Secrets</code>. LSA secrets can also be dumped from memory.(Citation: ired Dumping LSA Secrets)
Reg can be used to extract from the Registry. Mimikatz can be used to extract secrets from memory.(Citation: ired Dumping LSA Secrets)
Detection
(no detection guidance published)
Data sources
- (none listed)
References
- ATT&CK page: https://attack.mitre.org/techniques/T1003/004
- ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/