T1555 โ Credentials from Password Stores
Parent technique
Description
Adversaries may search for common password storage locations to obtain user credentials. Passwords are stored in several places on a system, depending on the operating system or application holding the credentials. There are also specific applications and services that store passwords to make them easier for users to manage and maintain, such as password managers and cloud secrets vaults. Once credentials are obtained, they can be used to perform lateral movement and access restricted information.
Sub-techniques
- T1555.001 โ Keychain
- T1555.002 โ Securityd Memory
- T1555.003 โ Credentials from Web Browsers
- T1555.004 โ Windows Credential Manager
- T1555.005 โ Password Managers
- T1555.006 โ Cloud Secrets Management Stores
Detected by EasySIEM
This project's own SigmaHQ-derived detection pipeline tags every compiled rule with the ATT&CK technique(s) it maps to -- if a rule in your install covers this technique, it shows up automatically on your own Grafana Alerts dashboard's "Top ATT&CK Techniques" panel, no lookup needed. This page exists so a click from there always lands here on easysiem.com, not on attack.mitre.org.