ATT&CKMatrixCredential Access

Credential Access

TA0006

Tactic.View on attack.mitre.org

About this tactic

The adversary is trying to steal account names and passwords.

Credential Access consists of techniques for stealing credentials like account names and passwords. Techniques used to get credentials include keylogging or credential dumping. Using legitimate credentials can give adversaries access to systems, make them harder to detect, and provide the opportunity to create more accounts to help achieve their goals.

Techniques17

IDNameSub-techniquesExamples
T1003OS Credential Dumping8203
T1040Network Sniffing028
T1056Input Capture4200
T1110Brute Force464
T1111Multi-Factor Authentication Interception09
T1187Forced Authentication03
T1212Exploitation for Credential Access02
T1528Steal Application Access Token013
T1539Steal Web Session Cookie029
T1552Unsecured Credentials897
T1555Credentials from Password Stores6178
T1556Modify Authentication Process925
T1557Adversary-in-the-Middle419
T1558Steal or Forge Kerberos Tickets525
T1606Forge Web Credentials23
T1621Multi-Factor Authentication Request Generation04
T1649Steal or Forge Authentication Certificates04

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.