| Domain | ID | Name | Use | |
|---|---|---|---|---|
| Enterprise | T1003 | .002 | OS Credential Dumping: Security Account Manager | |
| .004 | OS Credential Dumping: LSA Secrets | |||
| ID | Name | References |
|---|---|---|
| G0027 | Threat Group-3390 | |
| G0006 | APT1 | |
| G0011 | PittyTiger | |
| G0131 | Tonto Team | |
| G0060 | BRONZE BUTLER |
| ID | Name | Description |
|---|---|---|
| C0002 | Night Dragon |
During Night Dragon, threat actors used gsecdump to dump account hashes.[9] |