Umbra Wiki technique technique/T1555.005
Back to wiki

T1555.005 — Password Managers

provenance: imported · ATT&CK: T1555.005

T1555.005: Password Managers

MITRE ATT&CK® Enterprise technique

Tactics Credential Access
Platforms Linux, macOS, Windows
Permissions required
Version 1.1
Parent technique T1555

Description

Adversaries may acquire user credentials from third-party password managers.(Citation: ise Password Manager February 2019) Password managers are applications designed to store user credentials, normally in an encrypted database. Credentials are typically accessible after a user provides a master password that unlocks the database. After the database is unlocked, these credentials may be copied to memory. These databases can be stored as files on disk.(Citation: ise Password Manager February 2019)

Adversaries may acquire user credentials from password managers by extracting the master password and/or plain-text credentials from memory.(Citation: FoxIT Wocao December 2019)(Citation: Github KeeThief) Adversaries may extract credentials from memory via Exploitation for Credential Access.(Citation: NVD CVE-2019-3610) Adversaries may also try brute forcing via Password Guessing to obtain the master password of a password manager.(Citation: Cyberreason Anchor December 2019)

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1555/005
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/