This website uses cookies to ensure you get the best experience. Got it!
Empire. (2018, March 8). Empire keychaindump_decrypt Module. Retrieved April 14, 2022.
Open the source
None recorded.
Empire uses the command `/usr/bin/security dump-keychain -d` to read the keychain credential.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.