Skip to content
← LibraryTechnique entry
T1003.001Credential Access

LSASS Memory

Dump LSASS (mimikatz, procdump, comsvcs) to extract plaintext, NT hashes, and Kerberos tickets.

§ Where this technique fits

T1003.001 is catalogued under the Credential Access tactic of the offensive-security kill-chain. It appears in 5 approved dossiers in the registry, typically at step 6 on average.

Authoritative reference: attack.mitre.org/techniques/T1003/001/.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    BloodHound / SharpHound Enumeration
    AD-BLOODHOUND · Discovery
    seen 1×