SecretsDump is an open-source credential-dumping utility in the Impacket framework, used in security testing and malicious post-compromise activity against Windows systems and Active Directory environments. It extracts account information and password hashes from the Security Account Manager database, Local Security Authority secrets, and the Active Directory domain database. It supports credential extraction from saved databases and registry hives, and uses the Windows Remote Registry interface to retrieve credential material remotely. Its targets include Windows servers, workstations, and domain controllers.
Threat actors deploy SecretsDump after obtaining access to compromised systems to harvest local and domain credentials. Dragonfly, including activity tracked as Dragonfly 2.0, has dropped and executed the utility to dump password hashes. menuPass has used modified versions for credential dumping, and Memento ransomware operators deployed it on a compromised Windows server. It has also been packaged as a standalone executable using PyInstaller. SecretsDump is dual-use tooling rather than a distinct malware family; its credential-dumping functionality is used in both espionage and financially motivated intrusions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Dragonfly 2.0 dropped and executed SecretsDump to dump password hashes.
Secretsdump is a tool that allows the attacker to extract credential material from the Security Account Manager (SAM) database.
Table 15 lists “secretsdump.exe” and “secretsdump.py” as “Information dump” files potentially dropped onto victim systems.
For data extraction they relied on utilities such as secretsdump and mimikatz.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
The malicious actors use Mimikatz to extract plaintext credentials from memory; SAM and SECURITY registry hives are also dumped.
Windows registry hives containing password hashes, such as the SAM and SECURITY hives, are dumped.
Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as devices, users, and access rights.
OS Credential Dumping: LSA Secrets T1003.004 Dropped and executed SecretsDump to dump password hashes.
Stage 6 – DCSync: Replicate All Secrets... The tool requests a service ticket for DRSUAPI (the Directory Replication Service interface) and calls DRSGetNCChanges to pull all account hashes from the DC – including krbtgt , which enables Golden Ticket attacks, and all domain admin hashes.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A credential-dumping tool that abuses the Windows Remote Registry RPC interface to extract SAM and LSA secrets.
A credential dumping tool listed in the IoCs, typically used to extract account secrets from Windows systems.
A credential-dumping tool listed in the IOCs, typically used to extract secrets such as password hashes from Windows systems.
Impacket credential-dumping utility referenced as an IR hunting indicator for credential theft activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.