TA0006ATT&CK 14.1

TA0006Credential Access

Description

The adversary is trying to steal account names and passwords. Credential Access consists of techniques for stealing credentials like account names and passwords. Techniques used to get credentials include keylogging or credential dumping. Using legitimate credentials can give adversaries access to systems, make them harder to detect, and provide the opportunity to create more accounts to help achieve their goals.

Techniques in this tactic· 19

T1003
OS Credential Dumping
T1040
Network Sniffing
T1056
Input Capture
T1110
Brute Force
T1111
Multi-Factor Authentication Interception
T1167
Securityd Memory
T1187
Forced Authentication
T1212
Exploitation for Credential Access
T1503
Credentials from Web Browsers
T1522
Cloud Instance Metadata API
T1528
Steal Application Access Token
T1539
Steal Web Session Cookie
T1552
Unsecured Credentials
T1555
Credentials from Password Stores
T1556
Modify Authentication Process
T1557
Adversary-in-the-Middle
T1558
Steal or Forge Kerberos Tickets
T1606
Forge Web Credentials
T1621
Multi-Factor Authentication Request Generation

Sub-techniques in this tactic· 47

T1003.001T1003.002T1003.003T1003.004T1003.005T1003.006T1003.007T1003.008T1056.001T1056.002T1056.003T1056.004T1110.001T1110.002T1110.003T1110.004T1552.001T1552.002T1552.003T1552.004T1552.005T1552.006T1552.007T1552.008T1555.001T1555.002T1555.003T1555.004T1555.005T1555.006T1556.001T1556.002T1556.003T1556.004T1556.005T1556.006T1556.007T1556.008T1557.001T1557.002+7 more

References

  1. https://attack.mitre.org/tactics/TA0006

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

ATLAS
Exploitation for Credential Access
Tactic
Privilege Escalation
Tactic
Initial Access
Technique
OS Credential Dumping
Technique
Credentials from Password Stores
CAPEC
Capture Credentials via Keylogger
Sourced from MITRE ATT&CK Enterprise 14.1. Curated by Adam Lundqvist, Founder at SQUR.