Forge Web Credentials

T1606

Technique with 2 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may forge credential materials that can be used to gain access to web applications or Internet services. Web applications and services (hosted in cloud SaaS environments or on-premise servers) often use session cookies, tokens, or other materials to authenticate and authorize user access.

Adversaries may generate these credential materials in order to gain access to web resources. This differs from Steal Web Session Cookie, Steal Application Access Token, and other similar behaviors in that the credentials are new and forged by the adversary, rather than stolen or intercepted from legitimate users.

The generation of web credentials often requires secret values, such as passwords, Private Keys, or other cryptographic seed values. Adversaries may also forge tokens by taking advantage of features such as the `AssumeRole` and `GetFederationToken` APIs in AWS, which allow users to request temporary security credentials (i.e., Temporary Elevated Cloud Access), or the `zmprov gdpak` command in Zimbra, which generates a pre-authentication key that can be used to generate tokens for any user in the domain.

Once forged, adversaries may use these web credentials to access resources (ex: Use Alternate Authentication Material), which may bypass multi-factor and other authentication protection mechanisms.

Detection rules1

Rules on DetectionCode tagged with T1606 or one of its sub-techniques.

Sigma1

RuleLevelLog sourceTechnique
SAML Token Issuer Anomalyhighazure / NULLT1606

Splunk0

No Splunk rules are mapped to this technique yet.

Sub-techniques2

IDNameExamples
T1606.001Web Cookies1
T1606.002SAML Tokens2

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples0

No procedure examples are recorded for this technique.

References6

  1. AWS Temporary Security Credentials Open source
    AWS. (n.d.). Requesting temporary security credentials. Retrieved April 1, 2022.
  2. GitHub AWS-ADFS-Credential-Generator Open source
    Damian Hickey. (2017, January 28). AWS-ADFS-Credential-Generator. Retrieved September 27, 2024.
  3. Microsoft SolarWinds Customer Guidance Open source
    MSRC. (2020, December 13). Customer Guidance on Recent Nation-State Cyber Attacks. Retrieved December 17, 2020.
  4. Pass The Cookie Open source
    Rehberger, J. (2018, December). Pivot to the Cloud using Pass the Cookie. Retrieved April 5, 2019.
  5. Unit 42 Mac Crypto Cookies January 2019 Open source
    Chen, Y., Hu, W., Xu, Z., et. al. (2019, January 31). Mac Malware Steals Cryptocurrency Exchanges’ Cookies. Retrieved October 14, 2019.
  6. Zimbra Preauth Open source
    Zimbra. (2023, March 16). Preauth. Retrieved May 31, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.