We may earn an affiliate commission when you visit our partners.

Credential Dumping

Save
May 11, 2024 4 minute read

Credential Dumping is a technique used by attackers to obtain credentials from a compromised system by extracting them from memory. These credentials can include usernames, passwords, hashes, and other sensitive information that can be used to access accounts and systems.

Types of Credential Dumping

There are various techniques used for Credential Dumping, including:

  • Mimikatz: A popular tool used for Credential Dumping from memory, it can extract credentials from various processes and services.
  • ProcDump: A tool used to create memory dumps of running processes, which can then be analyzed for credentials.
  • RegRipper: A tool used to extract credentials from the Windows registry.
  • LSADump: A tool used to dump the contents of the Local Security Authority Subsystem Service (LSASS), which contains sensitive information such as credentials.
  • WDigest: A tool used to extract credentials from cached network authentication.

Preventing Credential Dumping

Organizations can implement several measures to prevent Credential Dumping, including:

Path to Credential Dumping

Take the first step.
We've curated two courses to help you on your path to Credential Dumping. Use these to develop your skills, build background knowledge, and put what you learn to practice.
Sorted from most relevant to least relevant:

Share

Help others find this page about Credential Dumping: by sharing it with your friends and followers:

Reading list

We've selected ten books that we think will supplement your learning. Use these to develop background knowledge, enrich your coursework, and gain a deeper understanding of the topics covered in Credential Dumping.
This document provides guidance on the use of digital identities in a variety of applications, including authentication, authorization, and digital signatures. It includes a section on credential dumping and provides recommendations for preventing and detecting credential dumping.
This document provides a comprehensive list of security and privacy controls for information systems and organizations, including controls for preventing and detecting credential dumping.
Provides a comprehensive overview of software security assessment, including a chapter on credential dumping. It is written by three experts in the field, Mark Dowd, John McDonald, and Justin Schuh, who have extensive experience in assessing and preventing software vulnerabilities.
Provides a comprehensive overview of the psychology of social engineering, including a section on credential dumping. It is written by Christopher Hadnagy, a leading expert in social engineering.
Provides a comprehensive overview of network security, including a section on credential dumping. It is written by three experts in the field, Stuart McClure, Joel Scambray, and George Kurtz, who have extensive experience in hacking and defending networks.
This document provides a list of the top 10 most critical security risks for web applications, including credential dumping. It is written by OWASP, a leading organization in web application security.
Provides a hands-on guide to penetration testing, including a section on credential dumping. It is written by two experts in the field, Georgia Weidman and Shane Macaulay, who have extensive experience in pen testing web applications.
Provides a comprehensive overview of web application security, including a section on credential dumping. It is written by two experts in the field, Dafydd Stuttard and Marcus Pinto, who have extensive experience in finding and exploiting security flaws in web applications.
Provides a comprehensive overview of secure coding, including a section on credential dumping. It is written by two experts in the field, Michael Howard and David LeBlanc, who have extensive experience in developing secure software.
Table of Contents
Our mission

OpenCourser helps millions of learners each year. People visit us to learn workspace skills, ace their exams, and nurture their curiosity.

Our extensive catalog contains over 50,000 courses and twice as many books. Browse by search, by topic, or even by career interests. We'll match you to the right resources quickly.

Find this site helpful? Tell a friend about us.

Affiliate disclosure

We're supported by our community of learners. When you purchase or subscribe to courses and programs or purchase books, we may earn a commission from our partners.

Your purchases help us maintain our catalog and keep our servers humming without ads.

Thank you for supporting OpenCourser.

© 2016 - 2025 OpenCourser