본문으로 바로가기

ATT&CK 기법 · Credential Access

OS Credential Dumping T1003

이 기법을 다룬 REVELARE 한국어 위협 분석 7 · Credential Access

이 기법을 다룬 분석

MITRE 공식 정의

Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password. Credentials can be obtained from OS caches, memory, or structures.(Citation: Brining MimiKatz to Unix) Credentials can then be used to perform [Lateral Movement](https://attack.mitre.org/tactics/TA0008) and access restricted information. Several of the tools mentioned in associated sub-techniques may be used by both adversaries

플랫폼: Linux, macOS, Windows
OS Credential Dumping (T1003) — ATT&CK 기법 분석 | REVELARE