TA0006ATT&CK 14.1
TA0006Credential Access
Description
The adversary is trying to steal account names and passwords.
Credential Access consists of techniques for stealing credentials like account names and passwords. Techniques used to get credentials include keylogging or credential dumping. Using legitimate credentials can give adversaries access to systems, make them harder to detect, and provide the opportunity to create more accounts to help achieve their goals.
Techniques in this tactic· 19
T1003
OS Credential Dumping
T1040
Network Sniffing
T1056
Input Capture
T1110
Brute Force
T1111
Multi-Factor Authentication Interception
T1167
Securityd Memory
T1187
Forced Authentication
T1212
Exploitation for Credential Access
T1503
Credentials from Web Browsers
T1522
Cloud Instance Metadata API
T1528
Steal Application Access Token
T1539
Steal Web Session Cookie
T1552
Unsecured Credentials
T1555
Credentials from Password Stores
T1556
Modify Authentication Process
T1557
Adversary-in-the-Middle
T1558
Steal or Forge Kerberos Tickets
T1606
Forge Web Credentials
T1621
Multi-Factor Authentication Request Generation
Sub-techniques in this tactic· 47
T1003.001T1003.002T1003.003T1003.004T1003.005T1003.006T1003.007T1003.008T1056.001T1056.002T1056.003T1056.004T1110.001T1110.002T1110.003T1110.004T1552.001T1552.002T1552.003T1552.004T1552.005T1552.006T1552.007T1552.008T1555.001T1555.002T1555.003T1555.004T1555.005T1555.006T1556.001T1556.002T1556.003T1556.004T1556.005T1556.006T1556.007T1556.008T1557.001T1557.002+7 more
References
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.