// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE PUB-ENTDTG 0600Z
ColdReconTechniquesT1003
Technique T1003

OS Credential Dumping

CLEARED FOR PUBLIC RELEASE · OPEN-SOURCE INTELLIGENCE
OS Credential Dumping (T1003) — a Credential Access technique, observed in public incident reporting.
MITRE ATT&CKT1003
TacticCredential Access
Incidents on file9

Detection & mitigation

Monitor for suspicious access to LSASS or DPAPI where WHFB keys are stored, such as unexpected process access or credential export tools. Enforce conditional access policies and investigate anomalous Entra ID authentications lacking MFA or biometric prompts.

Track this in real time.

ColdRecon watches the public signal so you don't have to — a daily brief and a live detection-coverage desk. Request clearance.

Request Clearance →