44
Groups Using This
1
Tactics
1
Platforms
21
Prevalence Rank
Description

Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS). After a user logs on, the system generates and stores a variety of credential materials in LSASS process memory. These credential materials can be harvested by an administrative user or SYSTEM and used to conduct Lateral Movement using Use Alternate Authentication Material. As well as in-memory techniques, the LSASS process memory can be dumped from the target host and analyzed on a local system. For example, on the target host use procdump: * procdump -ma lsass.exe lsass_dump Locally, mimikatz can be run using: * sekurlsa::Minidump lsassdump.dmp * sekurlsa::logonPasswords Built-in Windows tools such as `comsvcs.dll` can also be used: * rundll32.exe C:\Windows\System32\comsvcs.dll MiniDump PID lsass.dmp full Similar to Image File Execution Options Injection, the silent process exit mechanism can be abused to create a memory dump of `lsass.exe` through Windows Error Reporting (`WerFault.exe`). Windows Security Support Provider (SSP) DLLs are loaded into LSASS process at system start. Once loaded into the LSA, SSP DLLs have access to encrypted and plaintext passwords that are stored in Windows, such as any logged-on user's Domain password or smart card PINs. The SSP configuration is stored in two Registry keys: HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Security Packages and HKLM\SYSTEM\CurrentControlSet\Control\Lsa\OSConfig\Security Packages. An adversary may modify these Registry keys to add new SSPs, which will be loaded the next time the system boots, or when the AddSecurityPackage Windows API function is called. The following SSPs can be used to access credentials: * Msv: Interactive logons, batch logons, and service logons are done through the MSV authentication package. * Wdigest: The Digest Authentication protocol is designed for use with Hypertext Transfer Protocol (HTTP) and Simple Authentication Security Layer (SASL) exchanges. * Kerberos: Preferred for mutual client-server domain authentication in Windows 2000 and later. * CredSSP: Provides SSO and Network Level Authentication for Remote Desktop Services.

View MITRE record โ†—

Platforms
Windows
Groups Using T1003.001 (44)
G0094
Kimsuky
๐Ÿ‡ท๐Ÿ‡บ Russia130 techniques19 software
G0007
APT28
๐Ÿ‡ท๐Ÿ‡บ Russia93 techniques29 software
G0129
Mustang Panda
๐Ÿ‡ท๐Ÿ‡บ Russia85 techniques23 software
G0096
APT41
๐Ÿ‡จ๐Ÿ‡ณ China82 techniques32 software
G1017
Volt Typhoon
๐Ÿ‡จ๐Ÿ‡ณ China81 techniques17 software
G0034
Sandworm Team
๐Ÿ‡ท๐Ÿ‡บ Russia79 techniques27 software
G0050
APT32
๐Ÿ‡ป๐Ÿ‡ณ Vietnam78 techniques15 software
G0059
Magic Hound
๐Ÿ‡ฎ๐Ÿ‡ท Iran78 techniques13 software
G0049
OilRig
๐Ÿ‡ฎ๐Ÿ‡ท Iran76 techniques30 software
G0069
MuddyWater
๐Ÿ‡ฎ๐Ÿ‡ท Iran68 techniques21 software
G0102
Wizard Spider
๐Ÿ‡ท๐Ÿ‡บ Russia64 techniques22 software
G1055
VOID MANTICORE
๐Ÿ‡ฎ๐Ÿ‡ท Iran63 techniques0 software
G0027
Threat Group-3390
๐Ÿ‡จ๐Ÿ‡ณ China57 techniques24 software
G1051
Medusa Group
57 techniques5 software
G0087
APT39
๐Ÿ‡ฎ๐Ÿ‡ท Iran53 techniques11 software
G1016
FIN13
53 techniques4 software
G0065
Leviathan
๐Ÿ‡จ๐Ÿ‡ณ China50 techniques17 software
G1048
UNC3886
๐Ÿ‡จ๐Ÿ‡ณ China49 techniques8 software
G1003
Ember Bear
๐Ÿ‡ท๐Ÿ‡บ Russia47 techniques11 software
G0004
Ke3chang
๐Ÿ‡จ๐Ÿ‡ณ China46 techniques11 software
G1006
Earth Lusca
๐Ÿ‡จ๐Ÿ‡ณ China44 techniques9 software
G0022
APT3
๐Ÿ‡จ๐Ÿ‡ณ China44 techniques6 software
G0125
HAFNIUM
๐Ÿ‡จ๐Ÿ‡ณ China44 techniques6 software
G1054
MirrorFace
๐Ÿ‡จ๐Ÿ‡ณ China43 techniques16 software
G0117
Fox Kitten
๐Ÿ‡ฎ๐Ÿ‡ท Iran41 techniques5 software
G1039
RedCurl
๐Ÿ‡ท๐Ÿ‡บ Russia41 techniques0 software
G0060
BRONZE BUTLER
๐Ÿ‡จ๐Ÿ‡ณ China40 techniques14 software
G0037
FIN6
40 techniques12 software
G0061
FIN8
36 techniques11 software
G0143
Aquatic Panda
๐Ÿ‡จ๐Ÿ‡ณ China35 techniques6 software
G0119
Indrik Spider
๐Ÿ‡ท๐Ÿ‡บ Russia33 techniques8 software
G0064
APT33
๐Ÿ‡ฎ๐Ÿ‡ท Iran31 techniques16 software
G0093
GALLIUM
๐Ÿ‡ท๐Ÿ‡บ Russia31 techniques16 software
G1036
Moonstone Sleet
๐Ÿ‡ฐ๐Ÿ‡ต North Korea30 techniques1 software
G1023
APT5
๐Ÿ‡จ๐Ÿ‡ณ China29 techniques13 software
G0091
Silence
๐Ÿ‡ท๐Ÿ‡บ Russia28 techniques3 software
G1040
Play
26 techniques9 software
G0006
APT1
๐Ÿ‡จ๐Ÿ‡ณ China23 techniques17 software
G1030
Agrius
๐Ÿ‡ฎ๐Ÿ‡ท Iran22 techniques9 software
G0108
Blue Mockingbird
22 techniques2 software
G0077
Leafminer
๐Ÿ‡ฎ๐Ÿ‡ท Iran17 techniques4 software
G0068
PLATINUM
11 techniques3 software
G0107
Whitefly
9 techniques1 software
G0003
Cleaver
๐Ÿ‡ฎ๐Ÿ‡ท Iran5 techniques4 software
โ†‘