T1555 Credentials from Password Stores — ATT&CK Technique
Adversaries may search for common password storage locations to obtain user credentials. Passwords are stored in several places on a system, depending on the operating system or application holding the credentials. There are also specific applications and services that store passwords to make them easier for users to manage and maintain, such as password managers and cloud secrets vaults. Once credentials are obtained, they can be used to perform lateral movement and access restricted information.
Detection coverage (12)
- PUA - AWS TruffleHog Execution medium
- DPAPI Backup Keys And Certificate Export Activity IOC high
- HackTool - WinPwn Execution - ScriptBlock high
- Dump Credentials from Windows Credential Manager With PowerShell medium
- Enumerate Credentials from Windows Credential Manager With PowerShell medium
- HackTool - SecurityXploded Execution critical
- HackTool - WinPwn Execution high
- Suspicious Serv-U Process Pattern high
- MCP Postgres Suspicious Query
- Windows Credentials from Password Stores Creation
- Windows Credentials from Password Stores Deletion
- Windows Credentials from Password Stores Query
Malware using this technique
- MirrorStealer
- Carberp
- Mimikatz
- XLoader
- Lokibot
- MgBot
- Manjusaka
- Matryoshka
- CosmicDuke
- Prikormka
- PLEAD
- BeaverTail
- DarkGate
- NETWIRE
- OLDBAIT
- QuasarRAT
- RedLine Stealer
- Astaroth
- Agent Tesla
- LaZagne
- PinchDuke
- Mispadu
- Pupy
- PoshC2
- KGH_SPY