FORENSIA

ATT&CK · T1555.005 · sub-technique

Password Managers

Tactics: credential-access

About

Adversaries may acquire user credentials from third-party password managers. Password managers are applications designed to store user credentials, normally in an encrypted database. Credentials are typically accessible after a user provides a master password that unlocks the database. After the database is unlocked, these credentials may be copied to memory. These databases can be stored as files on disk. Adversaries may acquire user credentials from password managers by extracting the master password and/or plain-text credentials from memory. Adversaries may extract credentials from memory via Exploitation for Credential Access. Adversaries may also try brute forcing via Password Guessing to obtain the master password of a password manager.

Platforms: Linux, macOS, WindowsParent: T1555 Credentials from Password StoresMITRE ATT&CK ↗

Used by actors

7 known groups

Software

4 malware/tools implement this

TrickBotProtonMarkiRATInvisibleFerret

Corpus indicators tagged with this technique

16 indicators in the corpus carry T1555.005.