SharpSecDump is a .NET port of Impacket’s secretsdump.py used for credential dumping on Windows systems. The provided content states it is used to dump remote SAM and LSA secrets, aligning it with OS credential dumping activity against the Security Account Manager and LSA Secrets. Symantec reported that the China-linked threat actor APT15 used SharpSecDump to extract LSA credentials from victim systems during a campaign observed from late 2022 to early 2023. That campaign targeted foreign affairs ministries in Central and South American countries. In the same reporting, SharpSecDump was one of several post-compromise tools used alongside other credential-dumping utilities such as Mimikatz, Pypykatz, Safetykatz, Lazagne, and Quarks PwDump. High-confidence behavior directly mentioned in the content is limited to dumping remote SAM and LSA secrets and extracting LSA credentials from victim hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SharpSecDump – A .Net port of Impacket's secretsdump.py, used for dumping remote SAM and LSA secrets.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
.NET port of Impacket secretsdump.py used to dump remote SAM/LSA secrets for credential theft.
.NET credential dumping tool described as a port of Impacket's secretsdump.py, used to dump SAM and LSA secrets from Windows systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.