ATT&CKReferencesPentestlab Stored Credentials

Pentestlab Stored Credentials

netbiosX. (2017, April 19). Stored Credentials. Retrieved April 6, 2018.

Open the source

Techniques1

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples2

TechniqueUsed byProcedure example
T1552.002
Credentials in Registry
ToolReg

Reg may be used to find credentials in the Windows Registry.

T1552.002
Credentials in Registry
ToolPowerSploit

PowerSploit has several modules that search the Windows Registry for stored credentials: Get-UnattendedInstallFile, Get-Webconfig, Get-ApplicationHost, Get-SiteListPassword, Get-CachedGPPPassword, and Get-RegistryAutoLogon.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.