Lslsass (37a5ae23-3da5-4cbc-a21a-a7ef98a3b7cc)
Lslsass is a publicly-available tool that can dump active logon session password hashes from the lsass process. [Mandiant APT1]
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
APT1 (5307bba1-2674-4fbd-bfd5-1db1ae06fc5f) | Tidal Groups | Lslsass (37a5ae23-3da5-4cbc-a21a-a7ef98a3b7cc) | Tidal Software | 1 |