T1003: OS Credential Dumping
Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password. Credentials can be obtained from OS caches, memory, or structures.CitationBrining MimiKatz to Unix Credentials can then be used to perform Lateral Movement and access restricted information.
Several of the tools mentioned in associated sub-techniques may be used by both adversaries and professional security testers. Additional custom tools likely exist as well.
Security context for executives and security teams
OS Credential Dumping matters because it turns one compromised machine or privileged session into reusable login material: hashes, clear-text passwords, cached credentials, or directory secrets. For leaders, the business issue is not just credential theft; it is whether an attacker can use those credentials for lateral movement and access to restricted information across Windows, Linux, and macOS environments.
Executive priority
Treat T1003 as a core identity and incident-response readiness issue. Executives should ask whether privileged accounts, domain controllers, endpoint credential stores, and Linux/macOS credential exposure paths are governed, monitored, and recoverable. Budget and control prioritization should emphasize credential access protection, privileged account management, Active Directory configuration, hardened OS settings, and endpoint behavior prevention, because these controls determine how far an intrusion can spread after initial compromise.
Technical view
This is an enterprise credential-access technique covering Linux, macOS, and Windows, with Windows-heavy sub-techniques including LSASS memory, SAM, NTDS, LSA Secrets, Cached Domain Credentials, and DCSync, plus Linux paths such as proc filesystem and /etc/passwd or /etc/shadow. SOC and IR teams should validate visibility into sensitive memory access, registry or credential-store access, domain replication-like activity, privileged process tampering, and access to OS account databases. The related detection strategy, DET0234, points to correlating sensitive memory and registry access rather than relying on a single event.
Likely telemetry
- Endpoint process creation and command execution metadata
- Sensitive process memory access events, especially around authentication-related processes where available
- Windows Registry access to credential-related hives and secrets
- File access events for credential stores such as NTDS.dit, SAM, /etc/passwd, /etc/shadow, and proc filesystem paths
- Active Directory and domain controller replication-related logs or network activity relevant to DCSync-style behavior
Detection direction
- Validate whether telemetry exists on all stated platforms: Windows, Linux, and macOS; many programs have strong Windows coverage but weaker Unix-like credential-store monitoring.
- Correlate suspicious memory access, registry access, file access, and privileged account context instead of alerting only on known tool names, since ATT&CK notes both adversaries and professional security testers may use similar tools and custom tools may exist.
- Tune detections with authorized security testing activity in mind to reduce false positives while preserving visibility into unexpected access to credential material.
- For Active Directory environments, validate monitoring around domain controller data access and replication-related activity, especially where privileges could permit DCSync-like access.
- During incidents, treat confirmed credential dumping as a trigger for credential reset, privilege review, lateral movement scoping, and restricted-information access review.
Mitigation priorities
- Prioritize credential access protection and privileged account management to reduce who can reach credential material and how broadly stolen credentials can be reused.
- Harden Active Directory configuration, especially account permissions, logon policies, and domain administrative access paths.
- Protect privileged processes and authentication services from tampering or memory access where platform controls support it.
- Apply OS hardening to reduce unnecessary services, legacy exposure, and default credential-store accessibility.
- Use endpoint behavior prevention to block or disrupt credential-dumping behaviors rather than depending only on signatures.
Additional notes and limits
The object has no official ATT&CK detection text, so detection guidance is derived from the technique description, sub-technique relationships, external references, and the related DET0234 detection strategy. The group relationships show that multiple ATT&CK-tracked groups have used this technique, but this take does not infer current activity, targeting, or customer exposure.
Local validation is required to determine actual coverage. ATT&CK lists broad platforms and sub-techniques, but the supplied data does not specify exact event IDs, vendor detections, logging configurations, or guaranteed prevention outcomes. macOS-specific sub-technique detail is sparse in the supplied relationship context.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
OS Credential Dumping
Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password. Credentials can be obtained from OS caches, memory, or structures.CitationBrining MimiKatz to Unix Credentials can then be used to perform Lateral Movement and access restricted information.
Several of the tools mentioned in associated sub-techniques may be used by both adversaries and professional security testers. Additional custom tools likely exist as well.
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
All related ATT&CK context
No relationships are available in the current normalized data for this object.
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
