T1555Credentials from Password Stores
T1555 — Credentials from Password Stores is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 24 detection use cases covering it and 15 threat-intel articles citing it.
Credential Access
24Use cases
15Articles
6Sub-techniques
1Tactic
Sub-techniques (6)
Use cases covering this technique (24)
1Password item exfiltration attempt 1Password vault export attempted AWS Secrets Manager retrieval by unfamiliar principal GitHub personal access token cloning many repositories GitHub secrets-API enumeration Kubernetes Secret accessed [WEEKLY] Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN MCP Postgres Suspicious Query Windows Credentials from Password Stores Creation Windows Credentials from Password Stores Deletion Windows Credentials from Password Stores Query [LLM] n8n/Node child command accessing N8N_ENCRYPTION_KEY or host credential stores [LLM] CastleStealer/Starland RAT accessing browser credential stores and crypto wallets [LLM] Megalodon harvester: clustered read of ~/.ssh/id_*, ~/.kube/config, ~/.npmrc, ~/.docker/config.json in one session [LLM] Developer credential store read by Python or Node spawned from VS Code (Nx Console stealer pattern) [LLM] Burst credential-file harvest by VS Code / node process (Nx Console stealer behaviour) [LLM] Node.js process bulk-reading cloud & SCM credential files in single session [LLM] Node/npm/Bun process enumerating cloud, wallet, AI, and messaging credential file paths [LLM] Mini Shai-Hulud: Bun runtime executing `router_runtime.js` (2nd-stage stealer) [LLM] Access to OpenClaw credential store (~/.openclaw/credentials/, ~/.openclaw/config.json5) [LLM] GlassWorm Stage-3a Ledger impersonator binary execution (SHA256 06fab21d / SKuyzYcDD.exe) [LLM] TruffleHog secret-scanner execution on developer / CI host (SHA1-Hulud credential harvest) [LLM] macOS Text Replacements exfiltration via `defaults read NSUserDictionaryReplacementItems` [LLM] PTX-Player macOS infostealer artifacts (SHA256 + dropped /private/tmp logs)Articles citing this technique (15)
crit Begun, the Patch Wars have art-150