Critical severity Attack Technique

Credential Dumping

Stored or cached credentials are extracted from a host so they can be replayed elsewhere.

Overview

On Windows this means reading LSASS memory or the SAM database; on Linux, /etc/shadow and keyrings; in browsers, the encrypted password store paired with the user's DPAPI key.\nThe value comes from reuse: cached domain hashes and saved cloud tokens open doors far beyond the stolen machine.\nLSA protection, Credential Guard, and hardware-backed tokens raise the cost considerably.

Indicators of Compromise

Signals that suggest this is present on a system.

  • Unnamed or renamed security-tool processes reading LSASS
  • Unexpected access to /etc/shadow or registry hives
  • Massive numbers of NTLM authentications after a dump

Controls that stop it

  • Enforce Multi-Factor Authentication

    Require a second factor on every login, and make it phishing-resistant where you can: passkeys, FIDO2 security keys or certificate-based authentication. Push-based MFA is meaningfully better than no second factor, but it is still vulnerable to fatigue and real-time relay attacks. Apply it first to remote access, email and administrative accounts.

  • Apply Least Privilege Everywhere

    Give accounts, processes, tokens and service principals the minimum permissions needed, for the minimum time. Review admin rights and service accounts on a schedule, remove standing privilege, and prefer short-lived credentials over long-lived keys. Deny by default so a missing check fails closed rather than open.

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used