Credentials from Password Stores

T1555

Technique with 6 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may search for common password storage locations to obtain user credentials. Passwords are stored in several places on a system, depending on the operating system or application holding the credentials. There are also specific applications and services that store passwords to make them easier for users to manage and maintain, such as password managers and cloud secrets vaults. Once credentials are obtained, they can be used to perform lateral movement and access restricted information.

Detection rules33

Rules on DetectionCode tagged with T1555 or one of its sub-techniques.

Sigma19

RuleLevelLog sourceTechnique
HackTool - SecurityXploded Executioncriticalwindows / process_creationT1555
DPAPI Backup Keys And Certificate Export Activity IOChighwindows / file_eventT1555
HackTool - WinPwn Executionhighwindows / process_creationT1555 T1555.003
HackTool - WinPwn Execution - ScriptBlockhighwindows / ps_scriptT1555 T1555.003
Remote Thread Created In KeePass.EXEhighwindows / create_remote_threadT1555.005
SQLite Chromium Profile Data DB Accesshighwindows / process_creationT1555.003
Suspicious Key Manager Accesshighwindows / process_creationT1555.004
Suspicious Serv-U Process Patternhighwindows / process_creationT1555
Access to Browser Login Datamediumwindows / ps_scriptT1555.003
Access To Windows Credential History File By Uncommon Applicationsmediumwindows / file_accessT1555.004
Access To Windows DPAPI Master Keys By Uncommon Applicationsmediumwindows / file_accessT1555.004
Credentials from Password Stores - Keychainmediummacos / process_creationT1555.001
Dump Credentials from Windows Credential Manager With PowerShellmediumwindows / ps_scriptT1555
Enumerate Credentials from Windows Credential Manager With PowerShellmediumwindows / ps_scriptT1555
Potential Browser Data Stealingmediumwindows / process_creationT1555.003

Splunk14

RuleTypeRiskData sourceTechnique
Linux Auditd Find Credentials From Password ManagersTTPNULLLinux Auditd ExecveT1555.005
Linux Auditd Find Credentials From Password StoresTTPNULLLinux Auditd ExecveT1555.005
MacOS Keychains DumpedTTPNULLOsquery ResultsT1555.001
MCP Postgres Suspicious QueryHuntingNULLMCP ServerT1555
Non Chrome Process Accessing Chrome Default DirAnomalyNULLWindows Event Log Security 4663T1555.003
Non Firefox Process Access Firefox Profile DirAnomalyNULLWindows Event Log Security 4663T1555.003
Possible Browser Pass View ParameterHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1555.003
Windows Credentials Access via VaultCli ModuleAnomalyNULLSysmon EventID 7T1555.004
Windows Credentials from Password Stores Chrome Copied in TEMP DirTTPNULLSysmon EventID 11T1555.003
Windows Credentials from Password Stores CreationTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1555
Windows Credentials from Password Stores DeletionTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1555
Windows Credentials from Password Stores QueryAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1555
Windows Credentials from Web Browsers Saved in TEMP FolderTTPNULLSysmon EventID 11T1555.003
Windows Password Managers DiscoveryAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1555.005

Sub-techniques6

IDNameExamples
T1555.001Keychain12
T1555.002Securityd Memory1
T1555.003Credentials from Web Browsers89
T1555.004Windows Credential Manager14
T1555.005Password Managers13
T1555.006Cloud Secrets Management Stores9

Groups12

Software26

Show 2 more

Campaigns2

Procedure examples40

Groups12

Used byProcedure example
GroupAPT33

APT33 has used a variety of publicly available tools like LaZagne to gather credentials.

GroupAPT39

APT39 has used the Smartftp Password Decryptor tool to decrypt FTP passwords.

GroupAPT41

APT41 has obtained information about accounts, lists of employees, and plaintext and hashed passwords from databases.

GroupEvilnum

Evilnum can collect email credentials from victims.

GroupFIN6

FIN6 has used the Stealer One credential stealer to target e-mail and file transfer utilities including FTP.

GroupHEXANE

HEXANE has run `cmdkey` on victim machines to identify stored credentials.

GroupLeafminer

Leafminer used several tools for retrieving login and password information, including LaZagne.

GroupMalteiro

Malteiro has obtained credentials from mail clients via NirSoft MailPassView.

View all 12 groups examples

Software26

Used byProcedure example
MalwareAgent Tesla

Agent Tesla has the ability to steal credentials from FTP clients and wireless profiles.

MalwareAstaroth

Astaroth uses an external software known as NetPass to recover passwords.

MalwareBeaverTail

BeaverTail has collected keys stored for Solana stored in `.config/solana/id.json` and other login details associated with macOS within `/Library/Keychains/login.keychain` or for Linux within `/.local/share/keyrings`.

MalwareCarberp

Carberp's passw.plug plugin can gather account information from multiple instant messaging, email, and social media services, as well as FTP, VNC, and VPN clients.

MalwareCosmicDuke

CosmicDuke collects user credentials, including passwords, for various programs including popular instant messaging applications and email clients as well as WLAN keys.

MalwareDarkGate

DarkGate use Nirsoft Network Password Recovery or NetPass tools to steal stored RDP credentials in some malware versions.

MalwareKGH_SPY

KGH_SPY can collect credentials from WINSCP.

ToolLaZagne

LaZagne can obtain credentials from databases, mail, and WiFi across multiple platforms.

View all 26 software examples

Campaigns2

Used byProcedure example
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries configured a native CLI to gather a targeted elevated users password using `grep`.

CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used account credentials they obtained to attempt access to Group Managed Service Account (gMSA) passwords.

References1

  1. F-Secure The Dukes Open source
    F-Secure Labs. (2015, September 17). The Dukes: 7 years of Russian cyberespionage. Retrieved December 10, 2015.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.