- Tactics
- Credential Access
- Platforms
- Windows
- Reference
- attack.mitre.org/techniques/T1003.004
Description
Adversaries with SYSTEM access to a host may attempt to access Local Security Authority (LSA) secrets, which can contain a variety of different credential materials, such as credentials for service accounts.(Citation: Passcape LSA Secrets)(Citation: Microsoft AD Admin Tier Model)(Citation: Tilbury Windows Credentials) LSA secrets are stored in the registry at HKEY_LOCAL_MACHINE\SECURITY\Policy\Secrets. LSA secrets can also be dumped from memory.(Citation: ired Dumping LSA Secrets)
Reg can be used to extract from the Registry. Mimikatz can be used to extract secrets from memory.(Citation: ired Dumping LSA Secrets)
How GTK Cyber trains on this
GTK Cyber's Threat Hunting with Data Science course teaches you to build machine-learning detections for techniques like this across the MITRE ATT&CK framework, including the Credential Access tactic this technique falls under. Practitioner-led, focused on real detections, not memorizing technique IDs.
Related techniques
- T1003 - OS Credential Dumping
- T1040 - Network Sniffing
- T1056 - Input Capture
- T1110 - Brute Force
- T1111 - Multi-Factor Authentication Interception
- T1187 - Forced Authentication
- T1212 - Exploitation for Credential Access
- T1528 - Steal Application Access Token
- T1539 - Steal Web Session Cookie
- T1552 - Unsecured Credentials
- T1555 - Credentials from Password Stores
- T1556 - Modify Authentication Process