1200KM / simulation
T1555 Credentials from Password Stores — Attack Simulation
Adversaries may search for common password storage locations to obtain user credentials. Passwords are stored in several places on a system, depending on the operating system or application holding the credentials. There are also specific applications and services that store passwords to make them easier for users to manage and maintain, such as password managers and cloud secrets vaults. Once credentials are obtained, they can be used to…
Technique description
Adversaries may search for common password storage locations to obtain user credentials. Passwords are stored in several places on a system, depending on the operating system or application holding the credentials. There are also specific applications and services that store passwords to make them easier for users to manage and maintain, such as password managers and cloud secrets vaults. Once credentials are obtained, they can be used to…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- WinPwn - Loot local Credentials - lazagne
Procedure 079ee2e9-6f16-47ca-a635-14efcd994118; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Extract Windows Credential Manager via VBA
Procedure 234f9b7c-b53d-4f32-897b-b880a6c9ea7b; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Enumerate credentials from Windows Credential Manager using vaultcmd.exe [Windows Credentials]
Procedure 36753ded-e5c4-4eb5-bc3c-e8fba236878d; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Warzone/AveMaria RAT Style Credential Theft via Outlook Registry
Procedure 4a16a770-c1fc-494a-8131-022a0b147b3a; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Dump credentials from Windows Credential Manager With PowerShell [web Credentials]
Procedure 8fd5a296-6772-4766-9991-ff4e92af7240; elevation not declared required; cleanup not declared. Not executed or individually validated.
- WinPwn - Loot local Credentials - Wifi Credentials
Procedure afe369c2-b42e-447f-98a3-fb1f4e2b8552; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Enumerate credentials from Windows Credential Manager using vaultcmd.exe [Web Credentials]
Procedure bc071188-459f-44d5-901a-f8f2625b2d2e; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Dump credentials from Windows Credential Manager With PowerShell [windows Credentials]
Procedure c89becbe-1758-4e7d-a0f4-97d2188a23e3; elevation not declared required; cleanup not declared. Not executed or individually validated.
- WinPwn - Loot local Credentials - Decrypt Teamviewer Passwords
Procedure db965264-3117-4bad-b7b7-2523b7856b92; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.