Windows & Active Directory
MITRE ATT&CK™ OS Credential Dumping - Technique T1003
We may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password, from the operating system and software. Credentials can then be used to perform Lateral Movement and access restricted information.
AutoLogon RegistryCached Kerberos ticketsMITRE ATT&CK™ Steal or Forge Kerberos Tickets - Technique T1558DCSyncMITRE ATT&CK™ Sub-technique T1003.006DPAPI secretsMITRE ATT&CK™ Sub-technique T1555.003Group Policy PreferencesMITRE ATT&CK™ Sub-technique T1552.006Kerberos key listLSASS secretsMITRE ATT&CK™ Sub-technique T1003.001NTDS secretsMITRE ATT&CK™ Sub-technique T1003.003In-memory secretsSAM & LSA secretsMITRE ATT&CK™ Sub-techniques T1003.002, T1003.004 and T1003.005