Skip to content

Credential Dumping

Definition

Extraction of authentication credentials from operating system memory, the Windows SAM database, Active Directory, or credential stores. Tools such as Mimikatz target the LSASS process. Dumped credentials allow attackers to authenticate as other users without knowing their passwords in plaintext.

Targets
OS memory, SAM database, Active Directory, credential stores
Common tool
Mimikatz
Process targeted
LSASS
Effect
Authenticate as other users without plaintext passwords

Common questions

Why does credential dumping target the LSASS process specifically?+

LSASS caches authentication material such as hashes and Kerberos tickets in memory to support single sign-on, so extracting it gives an attacker reusable credentials without needing to crack a password.

What does credential dumping enable an attacker to do after initial access?+

It supports lateral movement and privilege escalation, since harvested credentials or hashes can be replayed against other systems on the network without the attacker knowing the original plaintext password.

Related terms

Lateral Movement
Attacker activity after initial compromise in which the threat actor traverses from one internal system to another, typically to escalate privileges, access...
Living-Off-the-Land (LotL)
An attack approach where the adversary uses tools and binaries already present on the target system, such as PowerShell, WMI, certutil, or...
MITRE ATT&CK
A publicly available knowledge base of adversary tactics, techniques, and procedures derived from real-world intrusion observations. Maintained by the MITRE Corporation. Techniques...
Tactic
The adversary's high-level objective at a given stage of the attack: for example, Initial Access, Execution, Persistence, Privilege Escalation, or Exfiltration. ATT&CK...
Technique
A specific method an adversary uses to achieve a tactic. Each technique has a unique identifier such as T1059 (Command and Scripting...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.