gsecdump

gsecdump is a publicly-available credential dumper used to obtain password hashes and LSA secrets from Windows operating systems. [1]

ID: S0008
Type: TOOL
Platforms: Windows
Version: 1.2
Created: 31 May 2017
Last Modified: 22 September 2022

Techniques Used

Domain ID Name Use
Enterprise T1003 .002 OS Credential Dumping: Security Account Manager

gsecdump can dump Windows password hashes from the SAM.[2]

.004 OS Credential Dumping: LSA Secrets

gsecdump can dump LSA secrets.[1]

Groups That Use This Software

Campaigns

ID Name Description
C0002 Night Dragon

During Night Dragon, threat actors used gsecdump to dump account hashes.[9]

References