1200KM / simulation
T1110.004 Credential Stuffing — Attack Simulation
Adversaries may use credentials obtained from breach dumps of unrelated accounts to gain access to target accounts through credential overlap. Occasionally, large numbers of username and password pairs are dumped online when a website or service is compromised and the user account credentials accessed. The information may be useful to an adversary attempting to compromise accounts by taking advantage of the tendency for users to use the same…
Technique description
Adversaries may use credentials obtained from breach dumps of unrelated accounts to gain access to target accounts through credential overlap. Occasionally, large numbers of username and password pairs are dumped online when a website or service is compromised and the user account credentials accessed. The information may be useful to an adversary attempting to compromise accounts by taking advantage of the tendency for users to use the same…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Brute Force:Credential Stuffing using Kerbrute Tool
Procedure 4852c630-87a9-409b-bb5e-5dc12c9ebcde; elevation not declared required; cleanup not declared. Not executed or individually validated.
- SSH Credential Stuffing From Linux
Procedure 4f08197a-2a8a-472d-9589-cd2895ef22ad; elevation not declared required; cleanup not declared. Not executed or individually validated.
- SSH Credential Stuffing From FreeBSD
Procedure a790d50e-7ebf-48de-8daa-d9367e0911d4; elevation not declared required; cleanup not declared. Not executed or individually validated.
- SSH Credential Stuffing From MacOS
Procedure d546a3d9-0be5-40c7-ad82-5a7d79e1b66b; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.