1200KM / simulation
T1555.003 Credentials from Web Browsers — Attack Simulation
Adversaries may acquire credentials from web browsers by reading files specific to the target browser. Web browsers commonly save credentials such as website usernames and passwords so that they do not need to be entered manually in the future. Web browsers typically store the credentials in an encrypted format within a credential store; however, methods exist to extract plaintext credentials from web browsers. For example, on Windows systems,…
Technique description
Adversaries may acquire credentials from web browsers by reading files specific to the target browser. Web browsers commonly save credentials such as website usernames and passwords so that they do not need to be entered manually in the future. Web browsers typically store the credentials in an encrypted format within a credential store; however, methods exist to extract plaintext credentials from web browsers. For example, on Windows systems,…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Simulating Access to Chrome Login Data - MacOS
Procedure 124e13e5-d8a1-4378-a6ee-a53cd0c7e369; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Simulating access to Opera Login Data
Procedure 28498c17-57e4-495a-b0be-cc1e36de408b; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Query Chrome Login Data In Place with sqlite3 - MacOS
Procedure 29d0c390-3cbc-4e4e-a52b-a1350ed836b7; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Simulating access to Chrome Login Data
Procedure 3d111226-d09a-4911-8715-fe11664f960d; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- BrowserStealer (Chrome / Firefox / Microsoft Edge)
Procedure 6f2c5c87-a4d5-4898-9bd1-47a55ecaf1dd; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Dump Chrome Login Data with esentutl
Procedure 70422253-8198-4019-b617-6be401b49fce; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- WinPwn - BrowserPwn
Procedure 764ea176-fb71-494c-90ea-72e9d85dce76; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- LaZagne.py - Dump Credentials from Firefox Browser
Procedure 87e88698-621b-4c45-8a89-4eaebdeaabb1; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Run Chrome-password Collector
Procedure 8c05b133-d438-47ca-a630-19cc464c4622; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- LaZagne - Credentials from Browser
Procedure 9a2915b3-3954-4cce-8c76-00fbf4dbd014; elevation required; cleanup not declared. Not executed or individually validated.
- Simulating access to Windows Edge Login Data
Procedure a6a5ec26-a2d1-4109-9d35-58b867689329; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Search macOS Safari Cookies
Procedure c1402f7b-67ca-43a8-b5f3-3143abedc01b; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Decrypt Mozilla Passwords with Firepwd.py
Procedure dc9cd677-c70f-4df5-bd1c-f114af3c2381; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- WebBrowserPassView - Credentials from Browser
Procedure e359627f-2d90-4320-ba5e-b0f878155bbe; elevation required; cleanup not declared. Not executed or individually validated.
- WinPwn - PowerSharpPack - Sharpweb for Browser Credentials
Procedure e5e3d639-6ea8-4408-9ecd-d5a286268ca0; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Simulating access to Windows Firefox Login Data
Procedure eb8da98a-2e16-4551-b3dd-83de49baa14c; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- WinPwn - Loot local Credentials - mimi-kittenz
Procedure ec1d0b37-f659-4186-869f-31a554891611; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Stage Popular Credential Files for Exfiltration
Procedure f543635c-1705-42c3-b180-efd6dc6e7ee7; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Molerats · G0021
- APT3 · G0022
- Sandworm Team · G0034
- FIN6 · G0037
- Stealth Falcon · G0038
- Patchwork · G0040
- OilRig · G0049
- APT33 · G0064
- APT37 · G0067
- MuddyWater · G0069
- Leafminer · G0077
- TA505 · G0092
- Kimsuky · G0094
- APT41 · G0096
- Inception · G0100
- ZIRCONIUM · G0128
- Ajax Security Team · G0130
- HEXANE · G1001
- LAPSUS$ · G1004
- Volt Typhoon · G1017
- Malteiro · G1026
- RedCurl · G1039
- APT42 · G1044
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.