Description
gsecdump is a credential dumping tool that extracts password hashes and other secrets from Windows systems, and cyberattackers abuse it to escalate access after a foothold. Because dumped hashes can enable pass the hash attacks across a network, the tool is a common post exploitation step in intrusions. Defenders should alert on unexpected appearances of the tool and monitor for the credential access behaviors it performs.
Stats
- First seen
- April 2022
- Last seen
- October 2026
Also known as
GsecDumpGsecdump
MITRE ATT&CK techniques
2 techniques across 1 tactics.
Associated groups
Associated campaigns
Alert name variants
| Alert Name |
|---|
| Application.Hacktool.Gsecdump.C |
| Application.Hacktool.Gsecdump.D |
| Application.Hacktool.Gsecdump.E |
| Application.Hacktool.Gsecdump.F |
| Dump:Application.Hacktool.Gsecdump.E |
| MemScan:Application.Hacktool.Gsecdump.E |
| Win32.Infostealer.GsecDump |
| Win64.Infostealer.GsecDump |