Skip to content

Credential Dumping

Intermediate users should understand that password extraction and credential dumping are critical techniques in red team operations, often used to escalate privileges or access systems post-compromise. This section explores methods like Mimikatz, password spraying, and credential stuffing, along with detection and mitigation strategies.


Mimikatz: In-Memory Credential Extraction

Mimikatz is a widely used tool for extracting credentials from memory (e.g., Windows LSASS processes) or leveraging Kerberos ticket-granting tickets (TGTs). It is commonly deployed in lateral movement scenarios.

Example: Extracting Logon Passwords

# Run Mimikatz in memory (e.g., via a payload)  
mimikatz.exe  
> sekurlsa::logonpasswords  
This command dumps credentials stored in memory, including NTLM hashes and clear-text passwords if available.

Example: Dumping Kerberos Tickets

> kerberos::list  
> kerberos::ptlist  
These commands list Kerberos tickets and pass-the-ticket (PtT) capabilities, enabling further access to network resources.

Note: Mimikatz requires administrative privileges and is often used in conjunction with tools like Invoke-Mimikatz (PowerShell) or memory exploitation techniques.


Password Spraying: Credential Overload

Password spraying involves attempting a small set of common passwords against multiple user accounts to bypass rate-limiting mechanisms. It is effective against systems with weak password policies.

Example: Using Hydra for Password Spraying

hydra -t 5 -m /login -u admin -p "Password1!" http://target.com/login  
This command attempts the password Password1! against the /login endpoint for the user admin, with 5 concurrent threads.

Key Considerations:
- Targets are often public-facing services (e.g., RDP, SSH, or web portals).
- Success depends on the target's password policy and user base.


Credential Stuffing: Reusing Stolen Credentials

Credential stuffing leverages previously leaked credentials (e.g., from data breaches) to brute-force login attempts. It exploits users' tendency to reuse passwords across services.

Example: Using Medusa for Credential Stuffing

medusa -u user@example.com -p "P@ssw0rd!" -M http -u http://target.com/login  
This command tests the credentials user@example.com:P@ssw0rd! against a web login endpoint.

Mitigation Focus:
- Monitor for unusual login patterns (e.g., multiple failed attempts from new IPs).
- Enforce account lockout policies and CAPTCHA mechanisms.


Detection and Mitigation Strategies

Detection

  • Mimikatz: Monitor for suspicious processes (e.g., mimikatz.exe) or memory dumps.
  • Password Spraying: Analyze login logs for repeated failed attempts against multiple accounts.
  • Credential Stuffing: Identify high-volume login attempts from known compromised credentials.

Mitigation

  • Enforce multi-factor authentication (MFA) to reduce credential reuse impact.
  • Implement rate limiting and account lockout policies.
  • Use SIEM tools to correlate login events and detect anomalies.

Key takeaways

  • Mimikatz is a powerful tool for in-memory credential extraction but requires elevated privileges.
  • Password spraying exploits weak password policies, while credential stuffing relies on reused credentials.
  • Detection and mitigation require a combination of logging, rate limiting, and user education.
  • All techniques are for authorized testing only and should not be used for unauthorized access.