ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1555.004×

9 examples

TechniqueUsed byProcedure example
T1555.004
Windows Credential Manager
MalwareRainyDay

RainyDay can use the QuarksPwDump tool to obtain local passwords and domain cached credentials.

T1555.004
Windows Credential Manager
MalwareROKRAT

ROKRAT can steal credentials by leveraging the Windows Vault mechanism.

T1555.004
Windows Credential Manager
MalwareKGH_SPY

KGH_SPY can collect credentials from the Windows Credential Manager.

T1555.004
Windows Credential Manager
MalwareValak

Valak can use a .NET compiled module named exchgrabber to enumerate credentials from the Credential Manager.

T1555.004
Windows Credential Manager
MalwareLizar

Lizar has a plugin that can retrieve credentials from Internet Explorer and Microsoft Edge using `vaultcmd.exe` and another that can collect RDP access credentials using the `CredEnumerateW` function.

T1555.004
Windows Credential Manager
ToolSILENTTRINITY

SILENTTRINITY can gather Windows Vault credentials.

T1555.004
Windows Credential Manager
ToolPowerSploit

PowerSploit contains a collection of Exfiltration modules that can harvest credentials from Windows vault credential objects.

T1555.004
Windows Credential Manager
ToolMimikatz

Mimikatz contains functionality to acquire credentials from the Windows Credential Manager.

T1555.004
Windows Credential Manager
ToolLaZagne

LaZagne can obtain credentials from Vault files.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.