// MITRE ATT&CK

🎯 Credential Access TA0006

MITRE ATT&CK techniques under the Credential Access tactic (52). Each explains the "how" the adversary pursues in this phase.

T1557
Adversary-in-the-Middle
T1110.001
Password Guessing
T1003
OS Credential Dumping
T1539
Steal Web Session Cookie
T1003.002
Security Account Manager
T1552.005
Cloud Instance Metadata API
T1555.002
Securityd Memory
T1110.002
Password Cracking
T1555.001
Keychain
T1003.004
LSA Secrets
T1606.002
SAML Tokens
T1003.007
Proc Filesystem
T1555.005
Password Managers
T1040
Network Sniffing
T1552.002
Credentials in Registry
T1558.005
Ccache Files
T1558.004
AS-REP Roasting
T1558
Steal or Forge Kerberos Tickets
T1555
Credentials from Password Stores
T1552
Unsecured Credentials
T1557.004
Evil Twin
T1555.003
Credentials from Web Browsers
T1557.003
DHCP Spoofing
T1552.004
Private Keys
T1557.001
Name Resolution Poisoning and SMB Relay
T1003.001
LSASS Memory
T1110.003
Password Spraying
T1003.005
Cached Domain Credentials
T1558.001
Golden Ticket
T1649
Steal or Forge Authentication Certificates
T1552.003
Shell History
T1552.001
Credentials In Files
T1606.001
Web Cookies
T1528
Steal Application Access Token
T1552.006
Group Policy Preferences
T1606
Forge Web Credentials
T1621
Multi-Factor Authentication Request Generation
T1552.008
Chat Messages
T1212
Exploitation for Credential Access
T1110
Brute Force
T1110.004
Credential Stuffing
T1187
Forced Authentication
T1557.002
ARP Cache Poisoning
T1555.006
Cloud Secrets Management Stores
T1003.008
/etc/passwd and /etc/shadow
T1558.002
Silver Ticket
T1555.004
Windows Credential Manager
T1111
Multi-Factor Authentication Interception
T1003.003
NTDS
T1558.003
Kerberoasting
T1003.006
DCSync
T1552.007
Container API

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.