Skip to content

Credential Dumping

Once you hold local privileges (admin/SYSTEM) on a host, the goal is to harvest credentials to move laterally and escalate in the domain. Windows stores secrets in several places: the local SAM database, the memory of the LSASS process, domain caches, LSA Secrets, DPAPI, browsers, and, on a DC, the NTDS.dit database with all the domain’s hashes. Credential dumping is the engine of lateral movement: a hash stolen here is someone’s session on the next host.

Windows keeps credentials in memory for Single Sign-On: while a user is logged on, their authentication material (NTLM hash, sometimes cleartext via WDigest, Kerberos tickets) lives in LSASS. Whoever is SYSTEM can read that memory. The attacker turns “admin on one host” into “the credentials of everyone who logged on there,” including domain admins who passed through that machine.

# remote with local-admin credentials
secretsdump.py domain/admin:pass@<host>
nxc smb <host> -u admin -p pass --sam --lsa
# local with the hives (requires SeBackup or SYSTEM)
reg save HKLM\SAM sam & reg save HKLM\SYSTEM sys & reg save HKLM\SECURITY sec
secretsdump.py -sam sam -system sys -security sec LOCAL

SAM yields local-account hashes; LSA Secrets holds service/task passwords, machine-account secrets, and sometimes cleartext credentials.

The jackpot: hashes and tickets of every user with an active session.

# mimikatz (Windows)
privilege::debug
sekurlsa::logonpasswords
sekurlsa::tickets /export
# dump the process and parse offline (stealthier)
procdump -ma lsass.exe lsass.dmp # then: pypykatz lsa minidump lsass.dmp
# nanodump / comsvcs.dll as a LOLBin for the dump

The AD database contains the hashes of all domain users.

# DCSync: request replication without touching the DC's disk (needs DS-Replication rights)
secretsdump.py domain/admin:pass@<DC> # uses DRSUAPI (DCSync)
mimikatz # lsadump::dcsync /user:krbtgt
# or copy NTDS.dit + SYSTEM (SeBackup / ntdsutil / VSS) and process offline

DCSync is the key technique: with replication rights (held by DA/EA and misdelegated accounts) you request hashes as if you were another DC, including krbtgt (→ Golden Ticket, see Active Directory Persistence).

  • DPAPI: browser, Wi-Fi, RDP, Credential Manager secrets (mimikatz dpapi::, SharpDPAPI).
  • Cached domain credentials (MSCache/DCC2): hashes of prior logons (slow cracking, hashcat 2100).
  • Browsers: cookies/passwords (SharpChrome). LSA protected (RunAsPPL): needs a bypass.
  • mimikatz — the standard (sekurlsa, lsadump, dpapi).
  • impacket secretsdump.py — remote SAM/LSA/NTDS/DCSync from Linux.
  • NetExec (nxc) --sam --lsa --ntds — mass multi-host dumping.
  • pypykatz / nanodump / procdump / comsvcs — LSASS dump and offline parsing.
  • SharpDPAPI / LaZagne — DPAPI and app credentials.

From local admin to credentials reusable across the network; from a DC, to all the domain’s hashes (including krbtgt) → full, persistent control. It’s the step that turns a compromised host into a domain compromise.

  • LSASS access: Sysmon event 10 with TargetImage lsass.exe and a memory-read GrantedAccess (0x1010/0x1410…) → dump signature.
  • DCSync: 4662 with the replication GUID (DS-Replication-Get-Changes) from a principal that is not a DC → very high fidelity.
  • reg save of SAM/SECURITY/SYSTEM; NTDS.dit reads via VSS; mimikatz/procdump execution over lsass.

Sysmon 10 (process access to lsass), 11 (dump to disk), DC replication auditing (4662 with DRSUAPI GUIDs), shadow-copy creation (VSS).

  • Credential Guard (isolates LSASS in VBS) and RunAsPPL (LSASS as a protected process) → stop direct dumping.
  • Disable WDigest (no more cleartext passwords in memory).
  • Restrict replication rights (DCSync) to DCs; audit them in BloodHound.
  • Tiering/PAW: keep DAs off workstations (don’t leave their credentials in user hosts’ LSASS); Protected Users.
  • LAPS (unique local admin per host → a stolen hash doesn’t open the whole network).

If a DC or domain credentials fell: rotate krbtgt twice, reset exposed accounts and affected machine accounts, rebuild compromised hosts, and review persistence (Golden Ticket, DCShadow).

  • LSASS/NTDS dumping is a ubiquitous TTP (MITRE T1003: .001 LSASS, .002 SAM, .003 NTDS, .006 DCSync).
  • mimikatz (Benjamin Delpy) is probably the most-used offensive tool in AD history.
  • NotPetya, Conti, BlackCat and nearly all modern ransomware dump LSASS and DCSync to reach DA.
  • CVE-2021-36934 (HiveNightmare) let a non-privileged user read SAM.
  • Host SAM + LSA Secrets (secretsdump/nxc)
  • LSASS dump (mimikatz/procdump/pypykatz) — cleartext passwords (WDigest)?
  • Cached domain credentials (DCC2) crackable
  • DPAPI: browsers, Credential Manager, RDP
  • Replication rights for DCSync? → krbtgt
  • On DC: full NTDS.dit (DCSync or VSS)
  • Is LSASS protected (RunAsPPL/Credential Guard)? Bypass needed?
  • Blue: detection of LSASS access and non-DC DCSync?