Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Credential Access/ T1555

T1555Credentials from Password Stores

T1555 — Credentials from Password Stores is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 24 detection use cases covering it and 15 threat-intel articles citing it.

Credential Access
View on the matrix → Filter Detection Library MITRE official spec ↗
24Use cases
15Articles
6Sub-techniques
1Tactic

Sub-techniques (6)

Use cases covering this technique (24)

1Password item exfiltration attempt Internal actions · alerting DD 1Password vault export attempted Internal actions · alerting DD AWS Secrets Manager retrieval by unfamiliar principal Internal actions · alerting DD GitHub personal access token cloning many repositories Internal actions · alerting DD GitHub secrets-API enumeration Internal actions · alerting DD Kubernetes Secret accessed Internal actions · alerting DD [WEEKLY] Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN Internal actions · alerting DSP MCP Postgres Suspicious Query ESCU actions · hunting P Windows Credentials from Password Stores Creation ESCU actions · alerting P Windows Credentials from Password Stores Deletion ESCU actions · alerting P Windows Credentials from Password Stores Query ESCU actions · hunting P [LLM] n8n/Node child command accessing N8N_ENCRYPTION_KEY or host credential stores Bespoke actions · alerting DSΣPDDCS [LLM] CastleStealer/Starland RAT accessing browser credential stores and crypto wallets Bespoke actions · hunting DSΣPDDCS [LLM] Megalodon harvester: clustered read of ~/.ssh/id_*, ~/.kube/config, ~/.npmrc, ~/.docker/config.json in one session Bespoke actions · hunting DSPDDCS [LLM] Developer credential store read by Python or Node spawned from VS Code (Nx Console stealer pattern) Bespoke actions · hunting DSPDDCS [LLM] Burst credential-file harvest by VS Code / node process (Nx Console stealer behaviour) Bespoke actions · hunting DSPDDCS [LLM] Node.js process bulk-reading cloud & SCM credential files in single session Bespoke actions · hunting DSPDDCS [LLM] Node/npm/Bun process enumerating cloud, wallet, AI, and messaging credential file paths Bespoke actions · hunting DSPDDCS [LLM] Mini Shai-Hulud: Bun runtime executing `router_runtime.js` (2nd-stage stealer) Bespoke actions · alerting DSΣPDD [LLM] Access to OpenClaw credential store (~/.openclaw/credentials/, ~/.openclaw/config.json5) Bespoke actions · alerting DSΣPDDCS [LLM] GlassWorm Stage-3a Ledger impersonator binary execution (SHA256 06fab21d / SKuyzYcDD.exe) Bespoke actions · alerting DSΣPDDCS [LLM] TruffleHog secret-scanner execution on developer / CI host (SHA1-Hulud credential harvest) Bespoke actions · alerting DSΣPDDCS [LLM] macOS Text Replacements exfiltration via `defaults read NSUserDictionaryReplacementItems` Bespoke actions · alerting DSΣPCS [LLM] PTX-Player macOS infostealer artifacts (SHA256 + dropped /private/tmp logs) Bespoke install · hunting DSΣPCS

Articles citing this technique (15)