Exploitation for Credential Access

T1212

Technique.View on attack.mitre.org

About this technique

Adversaries may exploit software vulnerabilities in an attempt to collect credentials. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code.

Credentialing and authentication mechanisms may be targeted for exploitation by adversaries as a means to gain access to useful credentials or circumvent the process to gain authenticated access to systems. One example of this is `MS14-068`, which targets Kerberos and can be used to forge Kerberos tickets using domain user permissions. Another example of this is replay attacks, in which the adversary intercepts data packets sent between parties and then later replays these packets. If services don't properly validate authentication requests, these replayed packets may allow an adversary to impersonate one of the parties and gain unauthorized access or privileges.

Such exploitation has been demonstrated in cloud environments as well. For example, adversaries have exploited vulnerabilities in public cloud infrastructure that allowed for unintended authentication token creation and renewal.

Exploitation for credential access may also result in Privilege Escalation depending on the process targeted or credentials obtained.

Detection rules7

Rules on DetectionCode tagged with T1212.

Sigma4

RuleLevelLog source
Audit CVE Eventcriticalwindows / NULL
Guacamole Two Users Sharing Session Anomalyhighlinux / NULL
Kerberos Manipulationhighwindows / NULL
Suspicious NTLM Authentication on the Printer Spooler Servicehighwindows / process_creation

Splunk3

RuleTypeRiskData source
Kubernetes Nginx Ingress LFITTPNULL
Kubernetes Nginx Ingress RFITTPNULL
Windows ConvertTo-AADIntBackdoor Execution Via PowerShell ScriptTTPNULLPowershell Script Block Logging 4104

Groups1

Software0

None recorded.

Campaigns1

Procedure examples2

Groups1

Used byProcedure example
GroupUNC3886

UNC3886 exploited CVE-2022-22948 in VMware vCenter to obtain encrypted credentials from the vCenter postgresDB.

Campaigns1

Used byProcedure example
CampaignLeviathan Australian Intrusions

Leviathan exploited vulnerable network appliances during Leviathan Australian Intrusions, leading to the collection and exfiltration of valid credentials.

References6

  1. ADSecurity Detecting Forged Tickets Open source
    Metcalf, S. (2015, May 03). Detecting Forged Kerberos Ticket (Golden Ticket & Silver Ticket) Use in Active Directory. Retrieved December 23, 2015.
  2. Bugcrowd Replay Attack Open source
    Bugcrowd. (n.d.). Replay Attack. Retrieved September 27, 2023.
  3. Comparitech Replay Attack Open source
    Justin Schamotta. (2022, October 28). What is a replay attack?. Retrieved September 27, 2023.
  4. Microsoft Midnight Blizzard Replay Attack Open source
    Microsoft Threat Intelligence. (2023, June 21). Credential Attacks. Retrieved September 12, 2024.
  5. Storm-0558 techniques for unauthorized email access Open source
    Microsoft Threat Intelligence. (2023, July 14). Analysis of Storm-0558 techniques for unauthorized email access. Retrieved September 18, 2023.
  6. Technet MS14-068 Open source
    Microsoft. (2014, November 18). Vulnerability in Kerberos Could Allow Elevation of Privilege (3011780). Retrieved December 23, 2015.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.