ryuki's blog

            • Corporate
            • FormulaX
            • Headless
            • Jab
            • Mist
            • Office
            • Perfection
            • Skyfall
            • WifineticTwo
            • Axlle
            • Blazorized
            • Blurry
            • BoardLight
            • Editorial
            • Freelancer
            • Ghost
            • Intuition
            • MagicGardens
            • Mailing
            • PermX
            • Runner
            • SolarLab
            • Caption
            • Chemistry
            • Cicada
            • Instant
            • Lantern
            • MonitorsThree
            • Resource
            • Sea
            • Sightless
            • Trickster
            • Yummy
            • BigBang
            • Checker
            • EscapeTwo
            • Administrator
            • Alert
            • BlockBlock
            • Certified
            • Compiled
            • GreenHorn
            • Heal
            • IClean
            • LinkVortex
            • UnderPass
            • Usage
            • Vintage
          • Escape
      root

      /

      tags

      /

      OS Credential Dumping (T1003)

      OS Credential Dumping (T1003)

      Jan 01, 19701 min read

      Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password.

      Tactics
      TA0006

      Sub-techniques
      T1003.001 T1003.002 T1003.003 T1003.004 T1003.005 T1003.006 T1003.007 T1003.008


      See: MITRE ATT&CK

      6 items with this tag.

      • Apr 26, 2025

        Vintage

        • hackthebox
        • hard
        • windows
        • assume-breach
        • dcsync
        • kerberoast
        • targeted-kerberoast
        • asreproast
        • pre2k
        • gmsa
        • password-spray
        • dpapi
        • T1003
        • T1003.006
        • T1078
        • T1078.002
        • T1087
        • T1087.002
        • T1098
        • T1098.007
        • T1110
        • T1110.002
        • T1110.003
        • T1555
        • T1555.004
      • Apr 19, 2025

        Administrator

        • hackthebox
        • windows
        • medium
        • kerberoast
        • targeted-kerberoast
        • dcsync
        • ftp
        • pwsafe
        • T1003
        • T1003.006
        • T1078
        • T1078.002
        • T1098
        • T1110
        • T1110.002
        • T1555
        • T1555.004
        • T1558
        • T1558.003
      • Apr 05, 2025

        Ghost

        • hackthebox
        • ctf
        • windows
        • insane
        • gitea
        • ldap-injection
        • goldensaml
        • SigmaPotato
        • sliver
        • amsi
        • adfs
        • gmsa
        • saml
        • mssql
        • linked-database
        • T1003
        • T1059
        • T1068
        • T1078
        • T1110
        • T1190
        • T1550
        • T1552
        • T1558
        • T1562
        • T1562.001
        • T1606
      • Feb 15, 2025

        Cicada

        • hackthebox
        • ctf
        • windows
        • easy
        • smb
        • secretsdump
        • SeBackup
        • sam
        • system
        • T1003
        • T1003.002
        • T1078
        • T1078.002
        • T1078.003
      • Oct 26, 2024

        Mist

        • hackthebox
        • ctf
        • windows
        • insane
        • adcs
        • ecs13
        • pluckcms
        • lnk
        • petitpotam
        • coerce
        • webdav
        • ntlmrelayx
        • certify
        • rubeus
        • shadow-credentials
        • mask
        • hashcat
        • oid-group-link
        • backup-operators
        • T1003
        • T1003.002
        • T1003.006
        • T1078
        • T1078.002
        • T1098
        • T1110
        • T1110.002
        • T1187
        • T1190
        • T1555
        • T1555.005
        • T1558
        • T1558.002
      • Oct 05, 2024

        Freelancer

        • hackthebox
        • ctf
        • windows
        • hard
        • qr
        • password-spray
        • memory
        • volatility
        • memprocfs
        • rbcd
        • sebackup
        • mssql
        • recycle-bin
        • server-operator
        • T1003
        • T1003.001
        • T1003.002
        • T1003.003
        • T1003.004
        • T1003.006
        • T1110
        • T1110.001
        • T1110.003
        • T1078
        • T1078.001
        • T1098
        • T1190
        • T1552
        • T1552.001
        • T1543
        • T1543.003

      Recent ...

      • Escape

        Jun 03, 2025

      • Checker

        May 31, 2025

      • EscapeTwo

        May 24, 2025

      • Season 8

        May 17, 2025

      • Heal

        May 17, 2025

      Created with ❤️ and Quartz

      • Mastodon
      • Bluesky
      • GitHub