1200KM / detection
T1555 Credentials from Password Stores — Detection Rules
Detection workspace for T1555 Credentials from Password Stores: 8 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- PUA - AWS TruffleHog Execution · experimental · medium · {"product":"aws","service":"cloudtrail"}
- DPAPI Backup Keys And Certificate Export Activity IOC · test · high · {"product":"windows","category":"file_event"}
- Dump Credentials from Windows Credential Manager With PowerShell · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Enumerate Credentials from Windows Credential Manager With PowerShell · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- HackTool - WinPwn Execution - ScriptBlock · test · high · {"category":"ps_script","product":"windows","definition":"Requirements: Script Block Logging must be enabled"}
- HackTool - SecurityXploded Execution · stable · critical · {"category":"process_creation","product":"windows"}
- HackTool - WinPwn Execution · test · high · {"category":"process_creation","product":"windows"}
- Suspicious Serv-U Process Pattern · test · high · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
T1555 Credentials from Password Stores
MATCH(access_to_password_store_path_or_api) AND process NOT_IN approved_password_clients -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0430 Detect Credentials Access from Password Stores
AN1198 Analytic 1198
Monitors suspicious access to password stores such as LSASS, DPAPI, Windows Credential Manager, or browser credential databases. Detects anomalous process-to-process access (e.g., Mimikatz accessing LSASS) and correlation of credential store file reads with execution of non-standard processes.
AN1199 Analytic 1199
Detects access to known password store files (e.g., /etc/shadow, GNOME Keyring, KWallet, browser credential databases). Monitors anomalous process read attempts and suspicious API calls that attempt to extract stored credentials.
AN1200 Analytic 1200
Monitors Keychain database access and suspicious invocations of security and osascript utilities. Correlates process execution with attempts to dump or unlock Keychain data.
AN1201 Analytic 1201
Detects attempts to access or enumerate cloud password/secrets storage services such as AWS Secrets Manager, Azure Key Vault, or GCP Secret Manager. Monitors API calls for abnormal enumeration or bulk retrieval of secrets.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.