Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Credential Access/ T1606.002

T1606.002SAML Tokens

T1606.002 — SAML Tokens is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 2 detection use cases covering it and 2 threat-intel articles citing it.

Credential Access
View on the matrix → Filter Detection Library MITRE official spec ↗
2Use cases
2Articles
0Sub-techniques
1Tactic

Use cases covering this technique (2)

[LLM] SAP NetWeaver SAML XML signature wrapping anomaly (CVE-2026-44748) Bespoke exploit · hunting DSPDD [LLM] ROADtools roadtx FOCI client-ID swap: refresh-token resource hop across MS Office FOCI app IDs Bespoke c2 · hunting DSPDD

Articles citing this technique (2)