Credential Dumping
Intermediate users should understand that password extraction and credential dumping are critical techniques in red team operations, often used to escalate privileges or access systems post-compromise. This section explores methods like Mimikatz, password spraying, and credential stuffing, along with detection and mitigation strategies.
Mimikatz: In-Memory Credential Extraction¶
Mimikatz is a widely used tool for extracting credentials from memory (e.g., Windows LSASS processes) or leveraging Kerberos ticket-granting tickets (TGTs). It is commonly deployed in lateral movement scenarios.
Example: Extracting Logon Passwords¶
This command dumps credentials stored in memory, including NTLM hashes and clear-text passwords if available.Example: Dumping Kerberos Tickets¶
These commands list Kerberos tickets and pass-the-ticket (PtT) capabilities, enabling further access to network resources.Note: Mimikatz requires administrative privileges and is often used in conjunction with tools like Invoke-Mimikatz (PowerShell) or memory exploitation techniques.
Password Spraying: Credential Overload¶
Password spraying involves attempting a small set of common passwords against multiple user accounts to bypass rate-limiting mechanisms. It is effective against systems with weak password policies.
Example: Using Hydra for Password Spraying¶
This command attempts the passwordPassword1! against the /login endpoint for the user admin, with 5 concurrent threads.
Key Considerations:
- Targets are often public-facing services (e.g., RDP, SSH, or web portals).
- Success depends on the target's password policy and user base.
Credential Stuffing: Reusing Stolen Credentials¶
Credential stuffing leverages previously leaked credentials (e.g., from data breaches) to brute-force login attempts. It exploits users' tendency to reuse passwords across services.
Example: Using Medusa for Credential Stuffing¶
This command tests the credentialsuser@example.com:P@ssw0rd! against a web login endpoint.
Mitigation Focus:
- Monitor for unusual login patterns (e.g., multiple failed attempts from new IPs).
- Enforce account lockout policies and CAPTCHA mechanisms.
Detection and Mitigation Strategies¶
Detection¶
- Mimikatz: Monitor for suspicious processes (e.g.,
mimikatz.exe) or memory dumps. - Password Spraying: Analyze login logs for repeated failed attempts against multiple accounts.
- Credential Stuffing: Identify high-volume login attempts from known compromised credentials.
Mitigation¶
- Enforce multi-factor authentication (MFA) to reduce credential reuse impact.
- Implement rate limiting and account lockout policies.
- Use SIEM tools to correlate login events and detect anomalies.
Key takeaways¶
- Mimikatz is a powerful tool for in-memory credential extraction but requires elevated privileges.
- Password spraying exploits weak password policies, while credential stuffing relies on reused credentials.
- Detection and mitigation require a combination of logging, rate limiting, and user education.
- All techniques are for authorized testing only and should not be used for unauthorized access.