Threadlinqs IntelligenceStart free

ATT&CK techniqueCredential Access

T1003 OS Credential Dumping

Credential AccessEnterprise

As of 2026-10-05, T1003 (OS Credential Dumping) appears in 291 tracked threats, first reported 2026-02-02 and most recently 2026-10-03, with linked actors including TeamPCP, Qilin, Sandworm; it most often appears alongside T1059 (Command and Scripting Interpreter).

Tracked threats
291129 critical, 133 high, 22 medium, 2 low
First seen
2026-02-02
Last seen
2026-10-03
Threat actors
105In the threats using it
Detection rules
157Blue tier and above

Data as of:

Activity timeline

T1003 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 98 reports, and 291 of the 291 threats were reported in the twelve months to 2026-10.

How adversaries use it

T1003 OS Credential Dumping is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix. Threadlinqs maps 291 of 2623 tracked threats (11.1%) to it; by severity that is 129 critical, 133 high, 22 medium, 2 low.

Threats that use T1003 most often also use T1059 Command and Scripting Interpreter (210 threats), T1190 Exploit Public-Facing Application (173 threats), T1071 Application Layer Protocol (166 threats), T1021 Remote Services (163 threats), T1082 System Information Discovery (161 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

105 tracked threat actors appear in the threats that use T1003; the most frequent are TeamPCP (13), Qilin (8), Sandworm (7), Static Tundra (6), Andariel (5).

Mitigations

MITRE ATT&CK lists 9 mitigations for T1003.

Data sources

Telemetry that can reveal T1003, per MITRE ATT&CK.

  • Active Directory — Active Directory Object Access
  • Command — Command Execution
  • File — File Access, File Creation
  • Network Traffic — Network Traffic Content, Network Traffic Flow
  • Process — OS API Execution, Process Access, Process Creation
  • Windows Registry — Windows Registry Key Access

Threat actors using it

Tracked threats

The 30 most recent of 291 tracked threats that use T1003.

Detection coverage

Threadlinqs maintains 157 detection rules mapped to T1003 (SPL 46, KQL 69, Sigma 42). Rule content is available to Blue tier accounts and above; this page shows counts only.

157 detection rules (SPL/KQL/Sigma) · Blue and above. Compare plans

Sub-techniques