Real-world descriptions of how a group, tool or campaign used a technique.
9 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1555.004 Windows Credential Manager |
MalwareRainyDay | RainyDay can use the QuarksPwDump tool to obtain local passwords and domain cached credentials. |
| T1555.004 Windows Credential Manager |
MalwareROKRAT | ROKRAT can steal credentials by leveraging the Windows Vault mechanism. |
| T1555.004 Windows Credential Manager |
MalwareKGH_SPY | KGH_SPY can collect credentials from the Windows Credential Manager. |
| T1555.004 Windows Credential Manager |
MalwareValak | Valak can use a .NET compiled module named exchgrabber to enumerate credentials from the Credential Manager. |
| T1555.004 Windows Credential Manager |
MalwareLizar | Lizar has a plugin that can retrieve credentials from Internet Explorer and Microsoft Edge using `vaultcmd.exe` and another that can collect RDP access credentials using the `CredEnumerateW` function. |
| T1555.004 Windows Credential Manager |
ToolSILENTTRINITY | SILENTTRINITY can gather Windows Vault credentials. |
| T1555.004 Windows Credential Manager |
ToolPowerSploit | PowerSploit contains a collection of Exfiltration modules that can harvest credentials from Windows vault credential objects. |
| T1555.004 Windows Credential Manager |
ToolMimikatz | Mimikatz contains functionality to acquire credentials from the Windows Credential Manager. |
| T1555.004 Windows Credential Manager |
ToolLaZagne | LaZagne can obtain credentials from Vault files. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.