T1555Techniquecredential-accessagent-callable

T1555Credentials from Password Stores

Platforms: Linux · macOS · Windows · IaaS

ATT&CK version: 14.1

What it is

Adversaries may search for common password storage locations to obtain user credentials. Passwords are stored in several places on a system, depending on the operating system or application holding the credentials. There are also specific applications and services that store passwords to make them easier for users to manage and maintain, such as password managers and cloud secrets vaults. Once credentials are obtained, they can be used to perform lateral movement and access restricted information.

ATT&CK tactics· 1

Credential Access

References

  1. https://attack.mitre.org/techniques/T1555
Sourced from MITRE ATT&CK Enterprise v14.1. Curated and contextualized for EU compliance use cases by Adam Lundqvist, Founder at SQUR.
T1555: Credentials from Password Stores | SQUR Knowledge Base