Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Credential Access T1003 — OS Credential Dumping KslKatz, KslDump, patched Mimikatz.”
3 distinct techniques documented for this family, organized by ATT&CK tactic.
This exposes IOCTL 0x222044 to local system administrators and grant them access to sensitive data in Protected Processes (For example, lsass.exe under PPL protection) | We can craft a specific service config and load the driver, because of the reasons mentioned previously, we don't need to modify the exist KSLD configs but create a totally new service. The driver would trust our project exe and bypass file/service/device name-based vulndrv protections.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A credential dumping tool used to extract Kerberos and LSASS secrets during post-compromise activity.
A credential-dumping and Kerberos-ticket extraction tool used or sourced by The Gentlemen operators.
Credential-dumping tooling used to obtain operating-system credentials.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.