Windows Credential Editor

Windows Credential Editor is a password dumping tool. [1]

ID: S0005
Associated Software: WCE
Type: TOOL
Platforms: Windows
Version: 1.1
Created: 31 May 2017
Last Modified: 30 March 2020

Techniques Used

Domain ID Name Use
Enterprise T1003 .001 OS Credential Dumping: LSASS Memory

Windows Credential Editor can dump credentials.[1]

Groups That Use This Software

ID Name References
G0093 GALLIUM

[2]

G0060 BRONZE BUTLER

[3][4]

G0037 FIN6

[5]

G0053 FIN5

[6][7]

G0027 Threat Group-3390

[8]

G0065 Leviathan

[9]

G0087 APT39

[10][11]

References