T1003 OS Credential Dumping
Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password. Credentials can be obtained from OS caches, memory, or structures.(Citation: Brining MimiKatz to Unix) Credentials can then be used to perform [Lateral Movement](https://attack.mitre.org/tactics/TA0008) and access restricted information. Several of…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- Antivirus - Password Dumper Signaturecriticalstable · antivirus
- HackTool - Rubeus Executioncriticalstable · windows
- Potential Russian APT Credential Theft Activitycriticalstable · windows
- APT31 Judgement Panda Activitycriticaltest · windows
- Active Directory Replication from Non Machine Accountcriticaltest · windows
- HackTool - Credential Dumping Tools Named Pipe Createdcriticaltest · windows
- HackTool - Dumpert Process Dumper Default Filecriticaltest · windows
- HackTool - Dumpert Process Dumper Executioncriticaltest · windows
- HackTool - Inveigh Executioncriticaltest · windows
- HackTool - QuarksPwDump Dump Filecriticaltest · windows
- HackTool - SafetyKatz Executioncriticaltest · windows
- HackTool - Windows Credential Editor (WCE) Executioncriticaltest · windows
- Hacktool Execution - Imphashcriticaltest · windows
- NotPetya Ransomware Activitycriticaltest · windows
- Potential Credential Dumping Via LSASS Process Clonecriticaltest · windows
- Potential Credential Dumping Via LSASS SilentProcessExit Techniquecriticaltest · windows
- WCE wceaux.dll Accesscriticaltest · windows
- Windows Credential Editor Registrycriticaltest · windows
- Credential Dumping Activity By Python Based Toolhighstable · windows
- Password Dumper Remote Thread in LSASShighstable · windows
- Potential LSASS Process Dump Via Procdumphighstable · windows
- Remote LSASS Process Access Through Windows Remote Managementhighstable · windows
- VolumeShadowCopy Symlink Creation Via Mklinkhighstable · windows
- Copying Sensitive Files with Credential Datahightest · windows
- Create Volume Shadow Copy with Powershellhightest · windows
Mostrando 25 de 107.
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.