// MITRE ATT&CK
🎯 Credential Access TA0006
Técnicas del framework MITRE ATT&CK clasificadas bajo la táctica Credential Access (52). Cada una explica el «cómo» que persigue el adversario en esta fase.
T1557
Adversary-in-the-Middle T1110.001
Password Guessing T1003
OS Credential Dumping T1539
Steal Web Session Cookie T1003.002
Security Account Manager T1552.005
Cloud Instance Metadata API T1555.002
Securityd Memory T1110.002
Password Cracking T1555.001
Keychain T1003.004
LSA Secrets T1606.002
SAML Tokens T1003.007
Proc Filesystem T1555.005
Password Managers T1040
Network Sniffing T1552.002
Credentials in Registry T1558.005
Ccache Files T1558.004
AS-REP Roasting T1558
Steal or Forge Kerberos Tickets T1555
Credentials from Password Stores T1552
Unsecured Credentials T1557.004
Evil Twin T1555.003
Credentials from Web Browsers T1557.003
DHCP Spoofing T1552.004
Private Keys T1557.001
Name Resolution Poisoning and SMB Relay T1003.001
LSASS Memory T1110.003
Password Spraying T1003.005
Cached Domain Credentials T1558.001
Golden Ticket T1649
Steal or Forge Authentication Certificates T1552.003
Shell History T1552.001
Credentials In Files T1606.001
Web Cookies T1528
Steal Application Access Token T1552.006
Group Policy Preferences T1606
Forge Web Credentials T1621
Multi-Factor Authentication Request Generation T1552.008
Chat Messages T1212
Exploitation for Credential Access T1110
Brute Force T1110.004
Credential Stuffing T1187
Forced Authentication T1557.002
ARP Cache Poisoning T1555.006
Cloud Secrets Management Stores T1003.008
/etc/passwd and /etc/shadow T1558.002
Silver Ticket T1555.004
Windows Credential Manager T1111
Multi-Factor Authentication Interception T1003.003
NTDS T1558.003
Kerberoasting T1003.006
DCSync T1552.007
Container API
Adversary-in-the-Middle T1110.001
Password Guessing T1003
OS Credential Dumping T1539
Steal Web Session Cookie T1003.002
Security Account Manager T1552.005
Cloud Instance Metadata API T1555.002
Securityd Memory T1110.002
Password Cracking T1555.001
Keychain T1003.004
LSA Secrets T1606.002
SAML Tokens T1003.007
Proc Filesystem T1555.005
Password Managers T1040
Network Sniffing T1552.002
Credentials in Registry T1558.005
Ccache Files T1558.004
AS-REP Roasting T1558
Steal or Forge Kerberos Tickets T1555
Credentials from Password Stores T1552
Unsecured Credentials T1557.004
Evil Twin T1555.003
Credentials from Web Browsers T1557.003
DHCP Spoofing T1552.004
Private Keys T1557.001
Name Resolution Poisoning and SMB Relay T1003.001
LSASS Memory T1110.003
Password Spraying T1003.005
Cached Domain Credentials T1558.001
Golden Ticket T1649
Steal or Forge Authentication Certificates T1552.003
Shell History T1552.001
Credentials In Files T1606.001
Web Cookies T1528
Steal Application Access Token T1552.006
Group Policy Preferences T1606
Forge Web Credentials T1621
Multi-Factor Authentication Request Generation T1552.008
Chat Messages T1212
Exploitation for Credential Access T1110
Brute Force T1110.004
Credential Stuffing T1187
Forced Authentication T1557.002
ARP Cache Poisoning T1555.006
Cloud Secrets Management Stores T1003.008
/etc/passwd and /etc/shadow T1558.002
Silver Ticket T1555.004
Windows Credential Manager T1111
Multi-Factor Authentication Interception T1003.003
NTDS T1558.003
Kerberoasting T1003.006
DCSync T1552.007
Container API
Fuente: MITRE ATT&CK®. ATT&CK es una marca registrada de The MITRE Corporation. Contenido con fines educativos.