SecretsDump is a credential-dumping tool in the Impacket framework used to extract account credentials, password hashes, and secrets from Windows systems and Active Directory environments. The provided content specifically associates it with dumping SAM and LSA secrets via the Windows Remote Registry interface (UUID 338cd001-2244-31f1-aaaa-900038001003), as well as obtaining account and password information from NTDS.dit on domain controllers. It is referenced alongside Mimikatz and other post-exploitation tooling for credential access, including use against local registry hives and domain credential stores. The content links SecretsDump to multiple threat-actor and intrusion contexts, including Dragonfly, which reportedly dropped and executed SecretsDump to dump password hashes, and menuPass, which used a modified secretsdump.py. It is also mentioned in reporting on hands-on-keyboard intrusions and ransomware-related activity as a tool attackers may deploy after initial access to harvest credentials for lateral movement and broader compromise. High-confidence indicators in the content include the SHA256 hash c3405d9c9d593d75d773c0615254e69d0362954384058ee970a3ec0944519c37 identified as Secretsdump.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Dragonfly has dropped and executed SecretsDump to dump password hashes.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Dump SAM hashes on Linux impacket-secretsdump -sam SAM -system SYSTEM local
Dragonfly has dropped and executed SecretsDump to dump password hashes.
secretsdump, DRSUAPI, and VSS 4 DRSBind behavior, DRSGetNCChanges defaults, VSS execution patterns
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A credential-dumping tool that abuses the Windows Remote Registry RPC interface to extract SAM and LSA secrets.
A credential dumping tool listed in the IoCs, typically used to extract account secrets from Windows systems.
A credential-dumping tool listed in the IOCs, typically used to extract secrets such as password hashes from Windows systems.
Impacket credential-dumping utility referenced as an IR hunting indicator for credential theft activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.