Credential Dumping

Credential dumping is a technique used under Credential Access to steal sensitive information such as usernames and passwords. Adversaries may employ methods like keylogging or credential dumping to obtain these credentials. With legitimate credentials in hand, attackers can gain unauthorized access to systems, evade detection more easily, and potentially create new accounts to further their objectives

Credential Dumping

Credential Dumping: GMSA

ReadGMSAPassword Attack is a technique where attackers abuse misconfigured Group Managed Service Accounts (gMSA) to retrieve their passwords. In Active Directory, ReadGMSAPassword should only be