Netskope Threat Labs

gsecdump

ATP Sandbox Adv. HeuristicsAV

gsecdump is a credential dumping tool that extracts password hashes and other secrets from Windows systems, and cyberattackers abuse it to escalate access after a foothold. Because dumped hashes can enable pass the hash attacks across a network, the tool is a common post exploitation step in intrusions. Defenders should alert on unexpected appearances of the tool and monitor for the credential access behaviors it performs.

First seen
April 2022
Last seen
October 2026
GsecDumpGsecdump

2 techniques across 1 tactics.

TA0006 Credential Access

Alert Name
Application.Hacktool.Gsecdump.C
Application.Hacktool.Gsecdump.D
Application.Hacktool.Gsecdump.E
Application.Hacktool.Gsecdump.F
Dump:Application.Hacktool.Gsecdump.E
MemScan:Application.Hacktool.Gsecdump.E
Win32.Infostealer.GsecDump
Win64.Infostealer.GsecDump