{"id":"T1003.004","name":"LSA Secrets","url":"https://attack.mitre.org/techniques/T1003/004","tactics":["credential-access"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0437","stix_id":"x-mitre-detection-strategy--c29886a9-676a-441a-adcd-6f239f8eb6b0","name":"Detection of LSA Secrets Dumping via Registry and Memory Extraction","url":"https://attack.mitre.org/detectionstrategies/DET0437","analytics":[{"id":"AN1212","stix_id":"x-mitre-analytic--a29288f5-c5d8-4e2d-8370-c4e21a64fc95","name":"Analytic 1212","description":"Detects adversary activity aimed at accessing LSA Secrets, including registry key export of HKEY_LOCAL_MACHINE\\SECURITY\\Policy\\Secrets or memory scraping via tools such as Mimikatz or PowerSploit's Invoke-Mimikatz.","url":"https://attack.mitre.org/detectionstrategies/DET0437#AN1212","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4663, 4670, 4656","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=10","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TargetObject","description":"Target registry paths like HKLM\\SECURITY\\Policy\\Secrets or variants can be tuned depending on OS version or registry redirection settings."},{"field":"ImageLoaded","description":"Module names such as `lsasrv.dll`, `sechost.dll`, or suspicious DLLs loaded by user processes may require tuning for known-good service operations."},{"field":"AccessMask","description":"Tuning based on whether processes are using specific sensitive access rights (e.g., 0x2 or 0x4)."},{"field":"TimeWindow","description":"Temporal window between registry access and command-line tool execution."}],"live":true,"detection_strategies":["DET0437"],"techniques":["T1003.004"]}],"live":true,"version":"1.0","techniques":["T1003.004"]}],"sigma_rules":[{"id":"06d71506-7beb-4f22-8888-e2e5e2ca7fd8","title":"Mimikatz Use","author":"Florian Roth (Nextron Systems), David ANDRE (additional keywords)","status":"test","level":"high","date":"2017-01-10","modified":"2022-01-05","description":"This method detects mimikatz keywords in different Eventlogs (some of them only appear in older Mimikatz version that are however still used by different threat groups)","references":["https://tools.thehacker.recipes/mimikatz/modules"],"logsource":{"product":"windows"},"tags":["attack.s0002","attack.lateral-movement","attack.credential-access","car.2013-07-001","car.2019-04-004","attack.t1003.002","attack.t1003.004","attack.t1003.001","attack.t1003.006"],"path":"rules/windows/builtin/win_alert_mimikatz_keywords.yml","techniques":["T1003.002","T1003.004","T1003.001","T1003.006"],"cves":[]},{"id":"252902e3-5830-4cf6-bf21-c22083dfd5cf","title":"Possible Impacket SecretDump Remote Activity","author":"Samir Bousseaden, wagga","status":"test","level":"high","date":"2019-04-03","modified":"2022-08-11","description":"Detect AD credential dumping using impacket secretdump HKTL","references":["https://web.archive.org/web/20230329153811/https://blog.menasec.net/2019/02/threat-huting-10-impacketsecretdump.html"],"logsource":{"product":"windows","service":"security"},"tags":["attack.credential-access","attack.t1003.002","attack.t1003.004","attack.t1003.003"],"path":"rules/windows/builtin/security/win_security_impacket_secretdump.yml","techniques":["T1003.002","T1003.004","T1003.003"],"cves":[]},{"id":"39a94fd1-8c9a-4ff6-bf22-c058762f8014","title":"DPAPI Domain Master Key Backup Attempt","author":"Roberto Rodriguez @Cyb3rWard0g","status":"test","level":"medium","date":"2019-08-10","modified":"2023-03-15","description":"Detects anyone attempting a backup for the DPAPI Master Key. This events gets generated at the source and not the Domain Controller.","references":["https://threathunterplaybook.com/hunts/windows/190620-DomainDPAPIBackupKeyExtraction/notebook.html"],"logsource":{"product":"windows","service":"security"},"tags":["attack.credential-access","attack.t1003.004"],"path":"rules/windows/builtin/security/win_security_dpapi_domain_masterkey_backup_attempt.yml","techniques":["T1003.004"],"cves":[]},{"id":"4976aa50-8f41-45c6-8b15-ab3fc10e79ed","title":"Credential Dumping Tools Service Execution - System","author":"Florian Roth (Nextron Systems), Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community","status":"test","level":"high","date":"2017-03-05","modified":"2022-11-29","description":"Detects well-known credential dumping tools execution via service execution events","references":["https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment"],"logsource":{"product":"windows","service":"system"},"tags":["attack.credential-access","attack.execution","attack.t1003.001","attack.t1003.002","attack.t1003.004","attack.t1003.005","attack.t1003.006","attack.t1569.002","attack.s0005"],"path":"rules/windows/builtin/system/service_control_manager/win_system_mal_creddumper.yml","techniques":["T1003.001","T1003.002","T1003.004","T1003.005","T1003.006","T1569.002"],"cves":[]},{"id":"4ac1f50b-3bd0-4968-902d-868b4647937e","title":"DPAPI Domain Backup Key Extraction","author":"Roberto Rodriguez @Cyb3rWard0g","status":"test","level":"high","date":"2019-06-20","modified":"2022-02-24","description":"Detects tools extracting LSA secret DPAPI domain backup key from Domain Controllers","references":["https://threathunterplaybook.com/hunts/windows/190620-DomainDPAPIBackupKeyExtraction/notebook.html"],"logsource":{"product":"windows","service":"security"},"tags":["attack.credential-access","attack.t1003.004"],"path":"rules/windows/builtin/security/win_security_dpapi_domain_backupkey_extraction.yml","techniques":["T1003.004"],"cves":[]},{"id":"8a1b2c3d-4e5f-6789-abcd-ef1234567890","title":"PUA - Memory Dump Mount Via MemProcFS","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2026-04-27","modified":null,"description":"Detects execution of MemProcFS a memory forensics tool with the '-device' parameter.\nMemProcFS mounts physical memory as a virtual file system, allowing direct access to process memory and system structures.\nThreat actors were seen abusing this utility to mount memory dumps and then extract sensitive information from processes like LSASS or extract registry hives to obtain credentials, LSA secrets, SAM data, and cached domain credentials.\nMemProcFS usage that is not part of authorized forensic analysis should be treated as suspicious and warrants further investigation.\n","references":["https://github.com/ufrisk/MemProcFS","https://0xdf.gitlab.io/2024/10/05/htb-freelancer.html#","https://www.huntress.com/blog/curling-for-data-a-dive-into-a-threat-actors-malicious-ttps"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.t1003","attack.t1003.001","attack.t1003.004","attack.t1003.002"],"path":"rules/windows/process_creation/proc_creation_win_pua_memprocfs.yml","techniques":["T1003","T1003.001","T1003.004","T1003.002"],"cves":[]},{"id":"8fbf3271-1ef6-4e94-8210-03c2317947f6","title":"Cred Dump Tools Dropped Files","author":"Teymur Kheirkhabarov, oscd.community","status":"test","level":"high","date":"2019-11-01","modified":"2025-10-25","description":"Files with well-known filenames (parts of credential dump software or files produced by them) creation","references":["https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.credential-access","attack.t1003.001","attack.t1003.002","attack.t1003.003","attack.t1003.004","attack.t1003.005"],"path":"rules/windows/file/file_event/file_event_win_cred_dump_tools_dropped_files.yml","techniques":["T1003.001","T1003.002","T1003.003","T1003.004","T1003.005"],"cves":[]},{"id":"92dae1ed-1c9d-4eff-a567-33acbd95b00e","title":"Possible Impacket SecretDump Remote Activity - Zeek","author":"Samir Bousseaden, @neu5ron","status":"test","level":"high","date":"2020-03-19","modified":"2021-11-27","description":"Detect AD credential dumping using impacket secretdump HKTL. Based on the SIGMA rules/windows/builtin/win_impacket_secretdump.yml","references":["https://web.archive.org/web/20230329153811/https://blog.menasec.net/2019/02/threat-huting-10-impacketsecretdump.html"],"logsource":{"product":"zeek","service":"smb_files"},"tags":["attack.credential-access","attack.t1003.002","attack.t1003.004","attack.t1003.003"],"path":"rules/network/zeek/zeek_smb_converted_win_impacket_secretdump.yml","techniques":["T1003.002","T1003.004","T1003.003"],"cves":[]},{"id":"961d0ba2-3eea-4303-a930-2cf78bbfcc5e","title":"HackTool - Credential Dumping Tools Named Pipe Created","author":"Teymur Kheirkhabarov, oscd.community","status":"test","level":"critical","date":"2019-11-01","modified":"2023-08-07","description":"Detects well-known credential dumping tools execution via specific named pipe creation","references":["https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment","https://image.slidesharecdn.com/zeronights2017kheirkhabarov-171118103000/75/hunting-for-credentials-dumping-in-windows-environment-57-2048.jpg?cb=1666035799"],"logsource":{"product":"windows","category":"pipe_created"},"tags":["attack.credential-access","attack.t1003.001","attack.t1003.002","attack.t1003.004","attack.t1003.005"],"path":"rules/windows/pipe_created/pipe_created_hktl_generic_cred_dump_tools_pipes.yml","techniques":["T1003.001","T1003.002","T1003.004","T1003.005"],"cves":[]},{"id":"a642964e-bead-4bed-8910-1bb4d63e3b4d","title":"HackTool - Mimikatz Execution","author":"Teymur Kheirkhabarov, oscd.community, David ANDRE (additional keywords), Tim Shelton","status":"test","level":"high","date":"2019-10-22","modified":"2023-02-21","description":"Detection well-known mimikatz command line arguments","references":["https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment","https://tools.thehacker.recipes/mimikatz/modules"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.t1003.001","attack.t1003.002","attack.t1003.004","attack.t1003.005","attack.t1003.006"],"path":"rules/windows/process_creation/proc_creation_win_hktl_mimikatz_command_line.yml","techniques":["T1003.001","T1003.002","T1003.004","T1003.005","T1003.006"],"cves":[]},{"id":"f0d1feba-4344-4ca9-8121-a6c97bd6df52","title":"Credential Dumping Tools Service Execution - Security","author":"Florian Roth (Nextron Systems), Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community","status":"test","level":"high","date":"2017-03-05","modified":"2022-11-29","description":"Detects well-known credential dumping tools execution via service execution events","references":["https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment"],"logsource":{"product":"windows","service":"security"},"tags":["attack.credential-access","attack.execution","attack.t1003.001","attack.t1003.002","attack.t1003.004","attack.t1003.005","attack.t1003.006","attack.t1569.002","attack.s0005"],"path":"rules/windows/builtin/security/win_security_mal_creddumper.yml","techniques":["T1003.001","T1003.002","T1003.004","T1003.005","T1003.006","T1569.002"],"cves":[]},{"id":"fd877b94-9bb5-4191-bb25-d79cbd93c167","title":"Dumping of Sensitive Hives Via Reg.EXE","author":"Teymur Kheirkhabarov, Endgame, JHasenbusch, Daniil Yugoslavskiy, oscd.community, frack113","status":"test","level":"high","date":"2019-10-22","modified":"2023-12-13","description":"Detects the usage of \"reg.exe\" in order to dump sensitive registry hives. This includes SAM, SYSTEM and SECURITY hives.","references":["https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment","https://eqllib.readthedocs.io/en/latest/analytics/aed95fc6-5e3f-49dc-8b35-06508613f979.html","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1003/T1003.md","https://www.wietzebeukema.nl/blog/windows-command-line-obfuscation","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1003.002/T1003.002.md#atomic-test-1---registry-dump-of-sam-creds-and-secrets"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.t1003.002","attack.t1003.004","attack.t1003.005","car.2013-07-001"],"path":"rules/windows/process_creation/proc_creation_win_reg_dumping_sensitive_hives.yml","techniques":["T1003.002","T1003.004","T1003.005"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}