Adversaries may search for common password storage locations to obtain user credentials.(Citation: F-Secure The Dukes) Passwords are stored in several places on a system, depending on the operating system or application holding the credentials. There are also specific applications and services that store passwords to make them easier for users to manage and maintain, such as password managers and cloud secrets vaults. Once credentials are obtained, they can be used to perform lateral movement and access restricted information.
View in MITRE ATT&CK®| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| action.malware.variety.Password dumper | Password dumper (extract credential hashes) | related-to | T1555 | Credentials from Password Stores | |
| attribute.confidentiality.data_disclosure | Confirmed or potential data disclosure | related-to | T1555 | Credentials from Password Stores |
| Technique ID | Technique Name | Number of Mappings |
|---|---|---|
| T1555.002 | Securityd Memory | 3 |
| T1555.001 | Keychain | 2 |
| T1555.005 | Password Managers | 2 |
| T1555.003 | Credentials from Web Browsers | 2 |
| T1555.006 | Cloud Secrets Management Stores | 2 |
| T1555.004 | Windows Credential Manager | 2 |