// MITRE ATT&CK

T1528 · Steal Application Access Token

🎯 Credential Access ContainersIaaSIdentity ProviderOffice SuiteSaaS

Adversaries can steal application access tokens as a means of acquiring credentials to access remote systems and resources. Application access tokens are used to make authorized API requests on behalf of a user or service and are commonly used as a way to access resources in cloud and container-bas...

How to detect & mitigate it

Detecting Steal Application Access Token starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.