ATT&CKReferencesEmpire Keychain Decrypt

Empire Keychain Decrypt

Empire. (2018, March 8). Empire keychaindump_decrypt Module. Retrieved April 14, 2022.

Open the source

Techniques1

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples1

TechniqueUsed byProcedure example
T1555.001
Keychain
ToolEmpire

Empire uses the command `/usr/bin/security dump-keychain -d` to read the keychain credential.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.