T1550.001 · Application Access Token
Sub-technique of T1550 · Use Alternate Authentication Material.
Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote systems. These tokens are typically stolen from users or services and used in lieu of login credentials. Application access tokens are...
How to detect & mitigate it
Related techniques
VNC T1080
Taint Shared Content T1021.004
SSH T1091
Replication Through Removable Media T1021.008
Direct Cloud VM Connections T1563.001
SSH Hijacking T1021.002
SMB/Windows Admin Shares T1550
Use Alternate Authentication Material
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.