Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Credential Access/ T1555.001

T1555.001Keychain

T1555.001 — Keychain is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 3 detection use cases covering it and 2 threat-intel articles citing it.

Credential Access
View on the matrix → Filter Detection Library MITRE official spec ↗
3Use cases
2Articles
0Sub-techniques
1Tactic

Use cases covering this technique (3)

MacOS Keychains Dumped ESCU actions · alerting P [LLM] macOS BlueNoroff stealer exfiltrating to Telegram bot (Aurora channel) Bespoke actions · alerting DSΣPCS [LLM] macOS.Gaslight keychain theft + collected_data.zip staging Bespoke actions · alerting DSΣPCS

Articles citing this technique (2)