OS Credential Dumping: Cached Domain Credentials

Adversaries may attempt to access cached domain credentials used to allow authentication to occur in the event a domain controller is unavailable.[1]

On Windows Vista and newer, the hash format is DCC2 (Domain Cached Credentials version 2) hash, also known as MS-Cache v2 hash.[2] The number of default cached credentials varies and can be altered per system. This hash does not allow pass-the-hash style attacks, and instead requires Password Cracking to recover the plaintext password.[3]

On Linux systems, Active Directory credentials can be accessed through caches maintained by software like System Security Services Daemon (SSSD) or Quest Authentication Services (formerly VAS). Cached credential hashes are typically located at /var/lib/sss/db/cache.[domain].ldb for SSSD or /var/opt/quest/vas/authcache/vas_auth.vdb for Quest. Adversaries can use utilities, such as tdbdump, on these database files to dump the cached hashes and use Password Cracking to obtain the plaintext password.[4]

With SYSTEM or sudo access, the tools/utilities such as Mimikatz, Reg, and secretsdump.py for Windows or Linikatz for Linux can be used to extract the cached credentials.[4]

Note: Cached credentials for Windows Vista are derived using PBKDF2.[2]

ID: T1003.005
Sub-technique of:  T1003
Platforms: Linux, Windows
Contributors: Ed Williams, Trustwave, SpiderLabs; Tim (Wadhwa-)Brown; Yves Yonan
Version: 1.1
Created: 21 February 2020
Last Modified: 15 October 2024

Procedure Examples

ID Name Description
G0064 APT33

APT33 has used a variety of publicly available tools like LaZagne to gather credentials.[5][6]

S0119 Cachedump

Cachedump can extract cached password hashes from cache entry information.[7]

S0349 LaZagne

LaZagne can perform credential dumping from MSCache to obtain account and password information.[8]

G0077 Leafminer

Leafminer used several tools for retrieving login and password information, including LaZagne.[9]

G0069 MuddyWater

MuddyWater has performed credential dumping with LaZagne.[10][11]

G0049 OilRig

OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access.[12][13][14][15]

S0439 Okrum

Okrum was seen using modified Quarks PwDump to perform credential dumping.[16]

S0192 Pupy

Pupy can use Lazagne for harvesting credentials.[17]

Mitigations

ID Mitigation Description
M1015 Active Directory Configuration

Consider adding users to the "Protected Users" Active Directory security group. This can help limit the caching of users' plaintext credentials.[18]

M1028 Operating System Configuration

Consider limiting the number of cached credentials (HKLM\SOFTWARE\Microsoft\Windows NT\Current Version\Winlogon\cachedlogonscountvalue)[19]

M1027 Password Policies

Ensure that local administrator accounts have complex, unique passwords across all systems on the network.

M1026 Privileged Account Management

Do not put user or admin domain accounts in the local administrator groups across systems unless they are tightly controlled, as this is often equivalent to having a local administrator account with the same password on all systems. Follow best practices for design and administration of an enterprise network to limit privileged account use across administrative tiers.

M1017 User Training

Limit credential overlap across accounts and systems by training users and administrators not to use the same password for multiple accounts.

Detection

ID Data Source Data Component Detects
DS0017 Command Command Execution

Monitor executed commands and arguments that may attempt to access cached domain credentials used to allow authentication to occur in the event a domain controller is unavailable.[1]. Remote access tools may contain built-in features or incorporate existing tools like Mimikatz. PowerShell scripts also exist that contain credential dumping functionality, such as PowerSploit's Invoke-Mimikatz module,[20] which may require additional logging features to be configured in the operating system to collect necessary information for analysis.Detection of compromised Valid Accounts in-use by adversaries may help as well.

Analytic 1 - Unusual access to cached domain credentials.

(index=security sourcetype="Powershell" EventCode=4104 Image="powershell.exe" CommandLine IN ("Invoke-Mimikatz", "Invoke-CachedCredentials"))OR(index=security sourcetype="linux_secure" (cmd IN ("mimikatz", "cachedump*")))

References