The sub-techniques beta is now live! Read the release blog post for more info.


pwdump is a credential dumper. [1]

ID: S0006
Type: TOOL
Platforms: Windows
Version: 1.0
Created: 31 May 2017
Last Modified: 17 October 2018

Techniques Used

Domain ID Name Use
Enterprise T1003 Credential Dumping

pwdump can be used to dump credentials.[1]

Groups That Use This Software

ID Name References
G0006 APT1 [2]
G0053 FIN5 [3]
G0045 menuPass [4]
G0027 Threat Group-3390 [5]
G0096 APT41 [6]