Sub-technique of T1555 Credentials from Password Stores.View on attack.mitre.org
Adversaries may acquire user credentials from third-party password managers. Password managers are applications designed to store user credentials, normally in an encrypted database. Credentials are typically accessible after a user provides a master password that unlocks the database. After the database is unlocked, these credentials may be copied to memory. These databases can be stored as files on disk.
Adversaries may acquire user credentials from password managers by extracting the master password and/or plain-text credentials from memory. Adversaries may extract credentials from memory via Exploitation for Credential Access.
Adversaries may also try brute forcing via Password Guessing to obtain the master password of a password manager.
Rules on DetectionCode tagged with T1555.005.
| Rule | Level | Log source |
|---|---|---|
| Remote Thread Created In KeePass.EXE | high | windows / create_remote_thread |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Linux Auditd Find Credentials From Password Managers | TTP | NULL | Linux Auditd Execve |
| Linux Auditd Find Credentials From Password Stores | TTP | NULL | Linux Auditd Execve |
| Windows Password Managers Discovery | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Used by | Procedure example |
|---|---|
| GroupFox Kitten | Fox Kitten has used scripts to access credential information from the KeePass database. |
| GroupIndrik Spider | Indrik Spider has accessed and exported passwords from password managers. |
| GroupLAPSUS$ | LAPSUS$ has accessed local password managers and databases to obtain further credentials from a compromised network. |
| GroupScattered Spider | Scattered Spider has searched for credentials in password vaults and Privileged Access Management (PAM) solutions including HashiCorp Vault. |
| GroupStorm-0501 | Storm-0501 has stolen credentials contained in the password manager Keepass by utilizing Find-KeePassConfig.ps1. |
| GroupThreat Group-3390 | Threat Group-3390 obtained a KeePass database from a compromised host. |
| GroupUNC3886 | UNC3886 has targeted KeyPass password database files for credential access. |
| Used by | Procedure example |
|---|---|
| MalwareInvisibleFerret | InvisibleFerret has utilized the command `ssh_zcp` to exfiltrate data from browser extensions and password managers via Telegram and FTP. |
| MalwareMarkiRAT | MarkiRAT can gather information from the Keepass password manager. |
| MalwareMini Shai-Hulud | Mini Shai-Hulud has gathered credentials stored in password managers to include password vaults. |
| MalwareProton | Proton gathers credentials in files for 1password. |
| MalwareTrickBot | TrickBot can steal passwords from the KeePass open source password manager. |
| Used by | Procedure example |
|---|---|
| CampaignOperation Wocao | During Operation Wocao, threat actors accessed and collected credentials from password managers. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.