secretsdump.py is an Impacket component used for Windows credential dumping. The provided content associates it with OS Credential Dumping (MITRE ATT&CK T1003), including dumping credentials from the SAM, SECURITY, SYSTEM, and NTDS.dit data stores, extracting LSA Secrets and cached credentials, and performing DCSync over the DRS Remote Protocol to remotely pull credential material from domain controllers. It is referenced as a tool that can obtain the same credential material as other dumping utilities and is specifically noted for use in DCSync scenarios. The content places it alongside tools such as Mimikatz, pwdump variants, and ProcDump in credential-access workflows. It is also described as relevant to domain backup key extraction and registry-hive-based credential theft. Threat reporting in the content mentions secretsdump.py in the context of ransomware intrusions and broader intrusion activity involving credential access, and notes that a .NET port of Impacket secretsdump.py (SharpSecDump) has been used by APT15. High-confidence behaviors directly mentioned include retrieval of SAM/registry-hive credential material, extraction of LSA Secrets, support for NTDS-related credential access, and remote credential replication via DCSync against Windows domain environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...the following tools could be used by an actor to obtain the same information: Secretsdump.py Note: This script is a component of Impacket...
12 distinct techniques documented for this family, organized by ATT&CK tactic.
“After reaching SYSTEM-level access, an attacker can collect credentials held by the Windows authentication process...”
“Process name lsass.exe Windows authentication process targeted for credential material during the credential-theft stage.”
Microsoft Defender reported "Behavior:Win32/RegDump.SA" ... Loading the file into regedit confirmed that we were dealing with a SAM hive... Impacket’s secretsdump.py uses exactly this naming pattern when remotely saving registry hives.
“Attackers can abuse Volume Shadow Copy Service to create a readable copy and bypass that lock. The stolen database is paired with a registry hive containing a key needed to unlock it offline.”
Impacket performs the registry operation remotely through the Windows Remote Registry service using the MS-RRP protocol. It connects to the winreg RPC interface over SMB (\pipe\winreg).
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Impacket tool used to perform DCSync-style credential extraction from domain controllers via replication protocols.
Credential dumping tool (commonly from Impacket) used to extract credentials (e.g., from AD/NTDS) to support privilege escalation and lateral movement in the intrusions.
Impacket-associated credential dumping script used to extract secrets (e.g., SAM/LSA secrets, cached credentials) from Windows systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.