OS Credential Dumping T1003

Tactic: Credential Access

Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password. Credentials can be obtained from OS caches, memory, or structures. Credentials can then be used to perform Lateral Movement and access restricted information.

Events covered

68 catalog events are tagged with this technique by at least one rule.

ProviderEventTitle
SysmonEvent ID 1Process creation
SysmonEvent ID 3Network connection
SysmonEvent ID 5Process terminated
SysmonEvent ID 7Image loaded
SysmonEvent ID 8CreateRemoteThread
SysmonEvent ID 10ProcessAccess
SysmonEvent ID 11FileCreate
SysmonEvent ID 12RegistryEvent (Object create and delete)
SysmonEvent ID 13RegistryEvent (Value Set)
SysmonEvent ID 14RegistryEvent (Key and Value Rename)
SysmonEvent ID 17PipeEvent (Pipe Created)
SysmonEvent ID 18PipeEvent (Pipe Connected)
SysmonEvent ID 23FileDelete (File Delete archived)
SysmonEvent ID 26FileDeleteDetected (File Delete logged)
Security-AuditingEvent ID 4624An account was successfully logged on.
Security-AuditingEvent ID 4648A logon was attempted using explicit credentials.
Security-AuditingEvent ID 4656A handle to an object was requested.
Security-AuditingEvent ID 4657A registry value was modified.
Security-AuditingEvent ID 4661A handle to an object was requested.
Security-AuditingEvent ID 4662An operation was performed on an object.
Security-AuditingEvent ID 4663An attempt was made to access an object.
Security-AuditingEvent ID 4672Special privileges assigned to new logon.
Security-AuditingEvent ID 4673A privileged service was called.
Security-AuditingEvent ID 4674An operation was attempted on a privileged object.
Security-AuditingEvent ID 4688A new process has been created.
Security-AuditingEvent ID 4689A process has exited.
Security-AuditingEvent ID 4690An attempt was made to duplicate a handle to an object.
Security-AuditingEvent ID 4692Backup of data protection master key was attempted.
Security-AuditingEvent ID 4697A service was installed in the system.
Security-AuditingEvent ID 4703A user right was adjusted.
Security-AuditingEvent ID 4728A member was added to a security-enabled global group.
Security-AuditingEvent ID 4732A member was added to a security-enabled local group.
Security-AuditingEvent ID 4756A member was added to a security-enabled universal group.
Security-AuditingEvent ID 4768A Kerberos authentication ticket (TGT) was requested.
Security-AuditingEvent ID 4769A Kerberos service ticket was requested.
Security-AuditingEvent ID 4904An attempt was made to register a security event source.
Security-AuditingEvent ID 4905An attempt was made to unregister a security event source.
Security-AuditingEvent ID 5136A directory service object was modified.
Security-AuditingEvent ID 5145A network share object was checked to see whether client can be granted desired access.
Security-AuditingEvent ID 5382Vault credentials were read.
Application-ErrorEvent ID 1000Faulting application name: Faulting_application_name, version: version, time stamp: 0xFaulting_module_name.
Defender-DeviceEventsOpenProcessApiCallProcess opened (OpenProcess API call)
Defender-DeviceEventsProcessPrimaryTokenModifiedProcess primary token modified
Defender-DeviceFileEventsanyFile activity
Defender-DeviceImageLoadEventsanyImage load
Defender-DeviceNetworkEventsanyNetwork activity
Defender-DeviceNetworkEventsNetworkSignatureInspectedNetwork signature inspected
Defender-DeviceProcessEventsanyProcess activity
Defender-DeviceProcessEventsProcessCreatedProcess created
Defender-IdentityLogonEventsanyIdentity logon activity
ESENTEvent ID 216Event ID 216
ESENTEvent ID 325Event ID 325
ESENTEvent ID 326Event ID 326
ESENTEvent ID 327Event ID 327
Linux-AuditdEvent ID 1124USER_TTY
Linux-AuditdEvent ID 1302PATH
Linux-AuditdEvent ID 1319TTY
Linux-AuditdEvent ID 1327PROCTITLE
Kernel-GeneralEvent ID 16The access history in hive HiveName was cleared updating KeysUpdated keys and creating DirtyPages modified pages.
NtfsEvent ID 98Volume DriveName (DeviceName) CorruptionActionState.
PowerShellEvent ID 4103Payload Context: ContextInfo User Data: UserData.
PowerShellEvent ID 4104Creating Scriptblock text (MessageNumber of MessageTotal).
WER-SystemErrorReportingEvent ID 1001The computer has rebooted from a bugcheck.
Windows-DefenderEvent ID 1121Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator.
PowerShellEvent ID 800Event ID 800
Service-Control-ManagerEvent ID 7045A service was installed in the system.
Sysmon-for-LinuxEvent ID 1Process Create
VSSAuditEvent ID 8222Event ID 8222

Authoring guide

These 423 rules share fields, values, and exclusions.

Fields filtered most (227 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine112contains 80, regex_match 23, wildcard 7, in 5, ends_with 2, match 2, eq 1, starts_with 1 --full , --name , -f , (?i)ntds\.dit, create
Image93ends_with 64, eq 15, starts_with 10, regex_match 8, contains 7, is_not_null 5, wildcard 2?:\, \\lsass\.exe$, \mpcopyaccelerator.exe, \msmpeng.exe, \ntdsutil.exe
EventID80eq 79, in 14688, 1, 10, 4104, 4656
process_name77eq 51, ends_with 10, in 9, regex_match 7, contains 3, starts_with 2, is_not_null 1, ne 1, wildcard 1cat, cmd.exe, powershell.exe, (?i)adexplorer(64)?|adexp\.exe, \lsass.exe
OriginalFileName56eq 54, in 2, contains 1, is_null 1powershell.exe, cmd.exe, reg.exe, appcmd.exe, dumpminitool.exe
host.os.type51eq 51
EventType45eq 32, in 10, ne 2, wildcard 1exec, exec_event, ProcessRollup2, start, open
event.type43eq 39, in 3, ne 1start, creation, change, process_started, deletion
TargetFilename33ends_with 15, contains 10, regex_match 9, wildcard 4, eq 3, starts_with 3.dmp, ?:\windows\system32\config\regback\sam, ?:\windows\system32\config\regback\security, ?:\windows\system32\config\regback\system, \.dmp$
TargetImage28ends_with 23, eq 5\lsass.exe, lsass.exe, ?:\windows\system32\lsass.exe, \\lsass.exe, c:\windows\system32\lsass.exe
process.args28eq 22, starts_with 9, wildcard 8, in 5, contains 4, match 1, ne 1--pid, -p, 1, -attach, -dump
TargetObject18contains 7, starts_with 4, eq 3, wildcard 3, ends_with 2hklm\sam\sam\domains\account\, hklm\security\cache, hklm\security\policy\secrets\, *\system\*controlset*\control\lsa\runasppl, *\system\*controlset*\control\securityproviders\wdigest\u...
GrantedAccess17eq 14, ends_with 5, contains 1, in 1, starts_with 10x1010, 0x1410, 0x1fffff, 0x1418, 0x1438
ScriptBlockText16contains 8, in 6, eq 3cert_system_store_local_machine, crypto::certificates, ).create(, *-dumpcr*, *[system.io.file]::copy*
ParentImage15contains 4, ends_with 4, eq 4, regex_match 3, is_not_null 1, wildcard 1\apache, \appdata\, %hacktool_contains, %hacktool_regex, .*

Top indicator values (2949 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
331078
EventIDeq
4688
20317
EventIDeq
1
13241
EventIDeq
10
1123
EventIDeq
4104
10269
EventIDeq
4656
719
EventIDeq
4662
615
EventIDeq
4663
635
EventIDeq
4103
5105
TargetImageends_with
\lsass.exe
1616
SubjectUserNameends_with
$
105
EventTypeeq
exec
9576
EventTypeeq
start
6391
EventTypeeq
open
552
EventTypein
exec
9201
EventTypein
exec_event
9149
EventTypein
start
8163
EventTypein
ProcessRollup2
7117
event.categoryeq
process
9142
CommandLinecontains
lsass
710
CommandLinecontains
create
629
CommandLinecontains
.dmp
510
CommandLinecontains
\windows\ntds\ntds.dit
55
DeviceProducteq
X Series
67
DeviceVendoreq
Vectra Networks
67
Imageends_with
\rundll32.exe
694
MessageTypeeq
2
621
Propertiescontains
1131f6aa-9c07-11d1-f79f-00c04fc2dcd2
66
Propertiescontains
1131f6ad-9c07-11d1-f79f-00c04fc2dcd2
66
Propertiescontains
89e95b76-444d-4c62-991a-0facbeda640c
66

Exclusions (798 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
SubjectUserNameends_with
$
11
process.code_signature.trustedeq
true
9
Imageeq
?:\windows\system32\svchost.exe
4
Imageeq
?:\windows\system32\werfault.exe
3
Imageeq
system
3
Imagestarts_with
c:\program files (x86)\
4
Imagestarts_with
c:\program files\
4
Imagestarts_with
c:\windows\system32\
4
Imagestarts_with
c:\windows\syswow64\
4
Imagestarts_with
c:\programdata\microsoft\windows defender\
3
Imagewildcard
?:\program files (x86)\*.exe
4
Imagewildcard
?:\program files\*.exe
4
Imagewildcard
?:\windows\system32\lsass.exe
4
Imageends_with
\mpcopyaccelerator.exe
3
Imageends_with
\msmpeng.exe
3

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 175 rules

Elastic 94 rules

Splunk 95 rules

Kusto 35 rules

YARA-L 21 rules

Panther 3 rules