Tactic.View on attack.mitre.org
The adversary is trying to steal account names and passwords.
Credential Access consists of techniques for stealing credentials like account names and passwords. Techniques used to get credentials include keylogging or credential dumping. Using legitimate credentials can give adversaries access to systems, make them harder to detect, and provide the opportunity to create more accounts to help achieve their goals.
| ID | Name | Sub-techniques | Examples |
|---|---|---|---|
| T1003 | OS Credential Dumping | 8 | 203 |
| T1040 | Network Sniffing | 0 | 28 |
| T1056 | Input Capture | 4 | 200 |
| T1110 | Brute Force | 4 | 64 |
| T1111 | Multi-Factor Authentication Interception | 0 | 9 |
| T1187 | Forced Authentication | 0 | 3 |
| T1212 | Exploitation for Credential Access | 0 | 2 |
| T1528 | Steal Application Access Token | 0 | 13 |
| T1539 | Steal Web Session Cookie | 0 | 29 |
| T1552 | Unsecured Credentials | 8 | 97 |
| T1555 | Credentials from Password Stores | 6 | 178 |
| T1556 | Modify Authentication Process | 9 | 25 |
| T1557 | Adversary-in-the-Middle | 4 | 19 |
| T1558 | Steal or Forge Kerberos Tickets | 5 | 25 |
| T1606 | Forge Web Credentials | 2 | 3 |
| T1621 | Multi-Factor Authentication Request Generation | 0 | 4 |
| T1649 | Steal or Forge Authentication Certificates | 0 | 4 |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.