Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Credential Access/ T1555.001

T1555.001Keychain

T1555.001 — Keychain is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 5 detection use cases covering it and 3 threat-intel articles citing it.

Credential Access
View on the matrix → Filter Detection Library MITRE official spec ↗
5Use cases
3Articles
0Sub-techniques
1Tactic

Use cases covering this technique (5)

MacOS Keychains Dumped ESCU actions · alerting P [LLM] AmnesiaStealer credential harvest: keychain dump, APFS TCC-bypass mount, and fake password prompt Bespoke actions · hunting DSΣPCS [LLM] macOS captured-password validation via dscl authonly + keychain unlock with cleartext password Bespoke actions · hunting DSΣPCS [LLM] macOS browser 'Safe Storage' master-key theft via security find-generic-password Bespoke actions · alerting DSΣPCS [LLM] macOS.Gaslight keychain theft + collected_data.zip staging Bespoke actions · alerting DSΣPCS

Articles citing this technique (3)