Credential Dumping
Definition
Extraction of authentication credentials from operating system memory, the Windows SAM database, Active Directory, or credential stores. Tools such as Mimikatz target the LSASS process. Dumped credentials allow attackers to authenticate as other users without knowing their passwords in plaintext.
- Targets
- OS memory, SAM database, Active Directory, credential stores
- Common tool
- Mimikatz
- Process targeted
- LSASS
- Effect
- Authenticate as other users without plaintext passwords
Common questions
Why does credential dumping target the LSASS process specifically?+
LSASS caches authentication material such as hashes and Kerberos tickets in memory to support single sign-on, so extracting it gives an attacker reusable credentials without needing to crack a password.
What does credential dumping enable an attacker to do after initial access?+
It supports lateral movement and privilege escalation, since harvested credentials or hashes can be replayed against other systems on the network without the attacker knowing the original plaintext password.
Related terms
- Lateral Movement
- Attacker activity after initial compromise in which the threat actor traverses from one internal system to another, typically to escalate privileges, access...
- Living-Off-the-Land (LotL)
- An attack approach where the adversary uses tools and binaries already present on the target system, such as PowerShell, WMI, certutil, or...
- MITRE ATT&CK
- A publicly available knowledge base of adversary tactics, techniques, and procedures derived from real-world intrusion observations. Maintained by the MITRE Corporation. Techniques...
- Tactic
- The adversary's high-level objective at a given stage of the attack: for example, Initial Access, Execution, Persistence, Privilege Escalation, or Exfiltration. ATT&CK...
- Technique
- A specific method an adversary uses to achieve a tactic. Each technique has a unique identifier such as T1059 (Command and Scripting...