Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1555.004 Windows Credential Manager |
ToolMimikatz | Mimikatz contains functionality to acquire credentials from the Windows Credential Manager. |
| T1555.004 Windows Credential Manager |
ToolLaZagne | LaZagne can obtain credentials from Vault files. |
| T1555.005 Password Managers |
CampaignOperation Wocao | During Operation Wocao, threat actors accessed and collected credentials from password managers. |
| T1555.005 Password Managers |
GroupIndrik Spider | Indrik Spider has accessed and exported passwords from password managers. |
| T1555.005 Password Managers |
GroupScattered Spider | Scattered Spider has searched for credentials in password vaults and Privileged Access Management (PAM) solutions including HashiCorp Vault. |
| T1555.005 Password Managers |
GroupUNC3886 | UNC3886 has targeted KeyPass password database files for credential access. |
| T1555.005 Password Managers |
GroupStorm-0501 | Storm-0501 has stolen credentials contained in the password manager Keepass by utilizing Find-KeePassConfig.ps1. |
| T1555.005 Password Managers |
GroupFox Kitten | Fox Kitten has used scripts to access credential information from the KeePass database. |
| T1555.005 Password Managers |
GroupLAPSUS$ | LAPSUS$ has accessed local password managers and databases to obtain further credentials from a compromised network. |
| T1555.005 Password Managers |
GroupThreat Group-3390 | Threat Group-3390 obtained a KeePass database from a compromised host. |
| T1555.005 Password Managers |
MalwareTrickBot | TrickBot can steal passwords from the KeePass open source password manager. |
| T1555.005 Password Managers |
MalwareInvisibleFerret | InvisibleFerret has utilized the command `ssh_zcp` to exfiltrate data from browser extensions and password managers via Telegram and FTP. |
| T1555.005 Password Managers |
MalwareMarkiRAT | MarkiRAT can gather information from the Keepass password manager. |
| T1555.005 Password Managers |
MalwareProton | Proton gathers credentials in files for 1password. |
| T1555.005 Password Managers |
MalwareMini Shai-Hulud | Mini Shai-Hulud has gathered credentials stored in password managers to include password vaults. |
| T1555.006 Cloud Secrets Management Stores |
GroupHAFNIUM | HAFNIUM has moved laterally from on-premises environments to steal passwords from Azure key vaults. |
| T1555.006 Cloud Secrets Management Stores |
GroupStorm-0501 | Storm-0501 has utilized Azure Key Vault to store the encryption key using the operation `Microsoft.KeyVault/Vaults/write`. |
| T1555.006 Cloud Secrets Management Stores |
MalwareShai-Hulud | Shai-Hulud has gathered secrets from AWS Secrets and GCP Secret Manager. Shai-Hulud has also gathered data from Azure Key Vault. |
| T1555.006 Cloud Secrets Management Stores |
ToolPacu | Pacu can retrieve secrets from the AWS Secrets Manager via the enum_secrets module. |
| T1555.006 Cloud Secrets Management Stores |
ToolTruffleHog | TruffleHog can obtain secrets from AWS Secrets and GCP Secret Manager. TruffleHog has also gathered passwords, secrets and API keys from source repositories, .env files, and git history. |
| T1555.006 Cloud Secrets Management Stores |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can enumerate multiple filesystem paths to extract credentials for AWS, GCP, and Azure including Identity Access Management (IAM) credentials. |
| T1555.006 Cloud Secrets Management Stores |
MalwareMini Shai-Hulud | Mini Shai-Hulud has captured credentials stored in cloud secret stores. |
| T1555.006 Cloud Secrets Management Stores |
MalwareCanisterWorm | CanisterWorm has gathered credentials from Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure. |
| T1555.006 Cloud Secrets Management Stores |
GroupTeamPCP | TeamPCP has used malware to exfiltrate cloud secrets from targeted environments including AWS, GCP, and Azure. |
| T1556 Modify Authentication Process |
CampaignArcaneDoor | ArcaneDoor included modification of the AAA process to bypass authentication mechanisms. |
| T1556 Modify Authentication Process |
GroupFIN13 | FIN13 has replaced legitimate KeePass binaries with trojanized versions to collect passwords from numerous applications. |
| T1556 Modify Authentication Process |
MalwareKessel | Kessel has trojanized the <sode>ssh_login</code> and |
| T1556 Modify Authentication Process |
MalwareEbury | Ebury can intercept private keys using a trojanized |
| T1556 Modify Authentication Process |
MalwareDRYHOOK | DRYHOOK has intercepted and logged user credentials by modifying the Perl module in Ivanti Connect Secure VPN edge-devices located within `/home/perl/DSAuth.pm`. |
| T1556 Modify Authentication Process |
ToolSILENTTRINITY | SILENTTRINITY can create a backdoor in KeePass using a malicious config file and in TortoiseSVN using a registry hook. |
| T1556.001 Domain Controller Authentication |
GroupChimera | Chimera's malware has altered the NTLM authentication program on domain controllers to allow Chimera to login without a valid credential. |
| T1556.001 Domain Controller Authentication |
MalwareSkeleton Key | Skeleton Key is used to patch an enterprise domain controller authentication process with a backdoor password. It allows adversaries to bypass the standard authentication system to use a defined password for all accounts authenticating to that domain controller. |
| T1556.002 Password Filter DLL |
GroupStrider | Strider has registered its persistence module on domain controllers as a Windows LSA (Local System Authority) password filter to acquire credentials any time a domain, local user, or administrator logs in or changes a password. |
| T1556.002 Password Filter DLL |
GroupOilRig | OilRig has registered a password filter DLL in order to drop malware. |
| T1556.002 Password Filter DLL |
GroupMirrorFace | MirrorFace has used a tool named MRSAStealer as a password filter to collect credentials on password changes. |
| T1556.002 Password Filter DLL |
MalwareRemsec | Remsec harvests plain-text credentials as a password filter registered on domain controllers. |
| T1556.003 Pluggable Authentication Modules |
MalwareSkidmap | Skidmap has the ability to replace the pam_unix.so file on an infected machine with its own malicious version that accepts a specific backdoor password for all users. |
| T1556.003 Pluggable Authentication Modules |
MalwareEbury | Ebury can deactivate PAM modules to tamper with the sshd configuration. |
| T1556.004 Network Device Authentication |
MalwareSYNful Knock | SYNful Knock has the capability to add its own custom backdoor password when it modifies the operating system of the affected network device. |
| T1556.004 Network Device Authentication |
MalwareDRYHOOK | DRYHOOK has patched victim appliances authentication routines to capture credentials in plaintext as users log in. |
| T1556.004 Network Device Authentication |
MalwareSLOWPULSE | SLOWPULSE can modify LDAP and two factor authentication flows by inspecting login credentials and forcing successful authentication if the provided password matches a chosen backdoor password. |
| T1556.006 Multi-Factor Authentication |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries modified two-factor settings within the FortiGate solution to `unset`. |
| T1556.006 Multi-Factor Authentication |
GroupScattered Spider | After compromising user accounts, Scattered Spider registers their own MFA tokens. |
| T1556.006 Multi-Factor Authentication |
MalwareSLOWPULSE | SLOWPULSE can insert malicious logic to bypass RADIUS and ACE two factor authentication (2FA) flows if a designated attacker-supplied password is provided. |
| T1556.006 Multi-Factor Authentication |
ToolAADInternals | The AADInternals `Set-AADIntUserMFA` command can be used to disable MFA for a specified user. |
| T1556.007 Hybrid Identity |
GroupAPT29 | APT29 has edited the `Microsoft.IdentityServer.Servicehost.exe.config` file to load a malicious DLL into the AD FS process, thereby enabling persistent access to any service federated with AD FS for a user with a specified User Principal Name. |
| T1556.007 Hybrid Identity |
ToolAADInternals | AADInternals can inject a malicious DLL (`PTASpy`) into the `AzureADConnectAuthenticationAgentService` to backdoor Azure AD Pass-Through Authentication. |
| T1556.009 Conditional Access Policies |
GroupScattered Spider | Scattered Spider has added additional trusted locations to Azure AD conditional access policies. |
| T1556.009 Conditional Access Policies |
GroupStorm-0501 | Storm-0501 has registered their own MFA method, and leveraged a victim hybrid joined server to circumvent Conditional Access Policies. |
| T1557 Adversary-in-the-Middle |
CampaignArcaneDoor | ArcaneDoor included interception of HTTP traffic to victim devices to identify and parse command and control information sent to the device. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.