// MITRE ATT&CK

T1589.001 · Credentials

🎯 Reconnaissance PRE Sub-technique

Sub-technique of T1589 · Gather Victim Identity Information.

Adversaries may gather credentials that can be used during targeting. Account credentials gathered by adversaries may be those directly associated with the target victim organization or attempt to take advantage of the tendency for users to use the same passwords across personal and business account...

How to detect & mitigate it

Detecting Credentials starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.