LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1003: OS Credential Dumping

Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password. Credentials can be obtained from OS caches, memory, or structures.CitationBrining MimiKatz to Unix Credentials can then be used to perform Lateral Movement and access restricted information.

Several of the tools mentioned in associated sub-techniques may be used by both adversaries and professional security testers. Additional custom tools likely exist as well.

EnterpriseT1003TechniqueObject v2.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

OS Credential Dumping matters because it turns one compromised machine or privileged session into reusable login material: hashes, clear-text passwords, cached credentials, or directory secrets. For leaders, the business issue is not just credential theft; it is whether an attacker can use those credentials for lateral movement and access to restricted information across Windows, Linux, and macOS environments.

Executive priority

Treat T1003 as a core identity and incident-response readiness issue. Executives should ask whether privileged accounts, domain controllers, endpoint credential stores, and Linux/macOS credential exposure paths are governed, monitored, and recoverable. Budget and control prioritization should emphasize credential access protection, privileged account management, Active Directory configuration, hardened OS settings, and endpoint behavior prevention, because these controls determine how far an intrusion can spread after initial compromise.

Technical view

This is an enterprise credential-access technique covering Linux, macOS, and Windows, with Windows-heavy sub-techniques including LSASS memory, SAM, NTDS, LSA Secrets, Cached Domain Credentials, and DCSync, plus Linux paths such as proc filesystem and /etc/passwd or /etc/shadow. SOC and IR teams should validate visibility into sensitive memory access, registry or credential-store access, domain replication-like activity, privileged process tampering, and access to OS account databases. The related detection strategy, DET0234, points to correlating sensitive memory and registry access rather than relying on a single event.

Likely telemetry

  • Endpoint process creation and command execution metadata
  • Sensitive process memory access events, especially around authentication-related processes where available
  • Windows Registry access to credential-related hives and secrets
  • File access events for credential stores such as NTDS.dit, SAM, /etc/passwd, /etc/shadow, and proc filesystem paths
  • Active Directory and domain controller replication-related logs or network activity relevant to DCSync-style behavior

Detection direction

  • Validate whether telemetry exists on all stated platforms: Windows, Linux, and macOS; many programs have strong Windows coverage but weaker Unix-like credential-store monitoring.
  • Correlate suspicious memory access, registry access, file access, and privileged account context instead of alerting only on known tool names, since ATT&CK notes both adversaries and professional security testers may use similar tools and custom tools may exist.
  • Tune detections with authorized security testing activity in mind to reduce false positives while preserving visibility into unexpected access to credential material.
  • For Active Directory environments, validate monitoring around domain controller data access and replication-related activity, especially where privileges could permit DCSync-like access.
  • During incidents, treat confirmed credential dumping as a trigger for credential reset, privilege review, lateral movement scoping, and restricted-information access review.

Mitigation priorities

  • Prioritize credential access protection and privileged account management to reduce who can reach credential material and how broadly stolen credentials can be reused.
  • Harden Active Directory configuration, especially account permissions, logon policies, and domain administrative access paths.
  • Protect privileged processes and authentication services from tampering or memory access where platform controls support it.
  • Apply OS hardening to reduce unnecessary services, legacy exposure, and default credential-store accessibility.
  • Use endpoint behavior prevention to block or disrupt credential-dumping behaviors rather than depending only on signatures.
Additional notes and limits

The object has no official ATT&CK detection text, so detection guidance is derived from the technique description, sub-technique relationships, external references, and the related DET0234 detection strategy. The group relationships show that multiple ATT&CK-tracked groups have used this technique, but this take does not infer current activity, targeting, or customer exposure.

Local validation is required to determine actual coverage. ATT&CK lists broad platforms and sub-techniques, but the supplied data does not specify exact event IDs, vendor detections, logging configurations, or guaranteed prevention outcomes. macOS-specific sub-technique detail is sparse in the supplied relationship context.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

OS Credential Dumping

Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password. Credentials can be obtained from OS caches, memory, or structures.CitationBrining MimiKatz to Unix Credentials can then be used to perform Lateral Movement and access restricted information.

Several of the tools mentioned in associated sub-techniques may be used by both adversaries and professional security testers. Additional custom tools likely exist as well.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.2
Created
Modified
Raw hash
0395545e0e026fd8...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.