FORENSIA

ATT&CK · T1555

Credentials from Password Stores

Tactics: credential-access

About

Adversaries may search for common password storage locations to obtain user credentials. Passwords are stored in several places on a system, depending on the operating system or application holding the credentials. There are also specific applications and services that store passwords to make them easier for users to manage and maintain, such as password managers and cloud secrets vaults. Once credentials are obtained, they can be used to perform lateral movement and access restricted information.

Platforms: IaaS, Linux, macOS, WindowsMITRE ATT&CK ↗

Used by actors

12 known groups

Software

25 malware/tools implement this

MimikatzPinchDukeCosmicDukePrikormkaOLDBAITMatryoshkaPupyNETWIREQuasarRATAgent TeslaLaZagneAstarothPoshC2PLEADLokibotCarberpKGH_SPYDarkGateMispaduMgBotManjusakaXLoaderRedLine StealerBeaverTailMirrorStealer

Corpus indicators tagged with this technique

4,907 indicators in the corpus carry T1555.

IndicatorTypeFamilySevSrc
44f6101dd8171133f53317bfd752300ehash802
8c935feec4bd05d5d918df308be417532fb42608fb989a08eab183e0ae699235sha256ransomware801
308351124c496d4f4effee65ab828506abf70385773c167ab1f32a7f030385achash802
d78f64551d1b31a31e5998e442f0debd458e011e05019b3951d9ddde997f8384hash802
59e3c4cb06331b4f2d78a9a0592f3747e573bd01c5a7650c26361d1e25520712sha256ransomware801
34d798a6c55e57ed0932b6499f4fbcb5454bdfca903307be101a0594b0ac07bcsha256ransomware801
670384fafb23140d96f2f8fe04a13fc8cc8e2a6e5e8c973e39b58d103c5fea92sha256phishing801
e20b35a8c30e076cdd0e1df05ba1ff2e418dbd39a674f084787cc0af2fda9e95sha256phishing801
6a69ea2ce3fea0ebfd7a32a1dfc4251bd4d7d8a4fbd44aaa47b82290d0414a9fhash802
6c700ca4e6d917c7aa9d964e98604a0349d9b8b4673df96a3f73a3d2d042635ahash802
fab69acd743f4111b749e3268690825c38822e62hash802
3f797a639bc855bc6d5471f327924b62d10900ddec49b970eca6604142bbb4besha256ransomware801
c8075bbff748096e1c6a1ea0aa67bb6762fdd7551427a12425b35b94c1f1ecf2sha256supply_chain801
50ffce607867d8fa8eaf6ef5cd25a3c0e7e4415e881b9e55c04a67bcddb74fdfsha256supply_chain801
64c7dd0a3a3ae49977ac05913d3878000cce14e5d8c1ee05b782bdfd648bde91sha256801
3d510977d60a44322f88100b515f06cb5ed83babc64247068d1a489595faa6c5sha256phishing801
b90988400cced319d260c4937f334ecc364785ed5c593cd2139965e62ca58173sha256phishing801
c099f965144bccd0b590f946659fc3c0747c54aef505b6caaca9078712f455fbsha256801
ad10ff9043d6f327045943635fcbd0c5918acb79dc998db92ee4c7dee5224710sha256801
3b6cb20891bce8602ce669187754871e402a1782031ef8b032cd007e3894bc5dhash802
4c9f271242f61f1a31b8146305e9a7ed512c521445d4f7a7a901e301307add3dsha256801
5864a697bd7b339f56b05405f29a097cd027cafdcc4e63c2aaeccccbf930605fsha256801
f6669bd504ce6b0e303be7ee47f2ebbc062989c88c41f0a3f436044a24869798sha256supply_chain801
07cd03e2082bcb0b890cc59ce4c770d1a095ac6f1ae9cf999f5542555c56f841sha256phishing801
91e523a46f3bb860ac2e5800b7e1ec89d75a2408410b9cd25eebc17c8d7a92bchash802
99813f3d0625e880158c68039c0e2fbf488db0be3db77cd1ce6d382644193f0ehash802
17832aa629524ef6e8d8d6e9b6b902a8d324b559e3c36dbd0e221ab1690be871sha256supply_chain801
164e322d6fbc62e254d73583acd7f39444c884d3f5e6a5d27db143fc25bc88b3sha256supply_chain801
282b9bc318ad1234cbd1b86424b784299b8be31545802a7c6b751166b814b990sha256supply_chain801
db972979d508e75fe730d3b72c2701470fbdaeaf8ebdd674744754fa44438ca5sha256ransomware801

Showing the top 30 by severity of 4,907.