T1003Tactic: Credential AccessOfficial MITRE ATT&CK Page

T1003: OS Credential Dumping

Adversaries may attempt to dump credentials to obtain account login and credential material, often in the form of password hashes or cleartext passwords.

Total Capable Binaries: 16
Windows: 15
Linux: 0
macOS: 1

Living-off-the-Land Matrix for T1003

Across 16 verified binaries
Windows0 payloads

Diskshadow.exe

Diskshadow.exe is a tool that exposes the functionality offered by the volume shadow copy Service (VSS).

Windows0 payloads

Esentutl.exe

Binary for working with Microsoft Joint Engine Technology (JET) database

Windows3 payloads

rdrleakdiag.exe

Microsoft Windows resource leak diagnostic tool

Sample Attack Vector:
rdrleakdiag.exe /p 940 /o {PATH_ABSOLUTE:folder} /fullmemdmp /wait 1
Windows0 payloads

Reg.exe

Used to manipulate the registry

Windows2 payloads

Rpcping.exe

Used to verify rpc connection

Sample Attack Vector:
rpcping -s 127.0.0.1 -e 1234 -a privacy -u NTLM
Windows2 payloads

Tttracer.exe

Used by Windows 1809 and newer to Debug Time Travel

Sample Attack Vector:
tttracer.exe {PATH_ABSOLUTE:.exe}
Windows0 payloads

wbadmin.exe

Windows Backup Administration utility

Windows0 payloads

Comsvcs.dll

COM+ Services

Windows0 payloads

adplus.exe

Debugging tool included with Windows Debugging Tools

Windows1 payloads

Createdump.exe

Microsoft .NET Runtime Crash Dump Generator (included in .NET Core)

Sample Attack Vector:
createdump.exe -n -f {PATH:.dmp} {PID}
Windows0 payloads

dsdbutil.exe

Dsdbutil is a command-line tool that is built into Windows Server. It is available if you have the AD LDS server role installed. Can be used as a command line utility to export Active Directory.

Windows0 payloads

Dump64.exe

Memory dump tool that comes with Microsoft Visual Studio

Windows0 payloads

DumpMinitool.exe

Dump tool part Visual Studio 2022

Windows0 payloads

ntdsutil.exe

Command line utility used to export Active Directory.

Windows2 payloads

Sqldumper.exe

Debugging utility included with Microsoft SQL.

Sample Attack Vector:
sqldumper.exe 464 0 0x0110
macOS2 payloads

osascript

Osascript executes Open Scripting Architecture (OSA) scripts such as AppleScript and JavaScript for Automation (JXA). Widely used in macOS malware to display convincing phishing dialogs, harvest credentials, control System Events, and execute shell commands.

Sample Attack Vector:
osascript -e 'display dialog "System Update requires your password to continue:" default answer "" with hidden answer with icon caution'
Sharon Ben Moshe
Curated & Verified by
Sharon Ben Moshe
Cybersecurity Researcher & Detection EngineerCheck Point