{"id":"T1212","name":"Exploitation for Credential Access","url":"https://attack.mitre.org/techniques/T1212","tactics":["credential-access"],"platforms":["Linux","Windows","macOS","Identity Provider"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0174","stix_id":"x-mitre-detection-strategy--13a856f3-66b2-4ab7-b73f-2a26e712e77f","name":"Detection Strategy for Exploitation for Credential Access","url":"https://attack.mitre.org/detectionstrategies/DET0174","analytics":[{"id":"AN0493","stix_id":"x-mitre-analytic--2d4a40e4-359f-49ac-9e3f-58e29497aa41","name":"Analytic 0493","description":"Detects adversary exploitation of authentication mechanisms or credential validation processes. Defender perspective includes forged Kerberos tickets (e.g., MS14-068), abnormal LSASS memory access, replayed authentication attempts, and unexpected crashes of authentication services. Multi-event correlation ties exploitation attempts to abnormal process creation, service instability, and suspicious authentication events.","url":"https://attack.mitre.org/detectionstrategies/DET0174#AN0493","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4768, 4769, 4770","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=10","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"MonitoredAccounts","description":"High-value accounts (e.g., Domain Admins) for anomalous ticket issuance or replay activity."},{"field":"ReplayDetectionWindow","description":"Time window for correlating duplicate or replayed Kerberos authentications."}],"live":true,"detection_strategies":["DET0174"],"techniques":["T1212"]},{"id":"AN0494","stix_id":"x-mitre-analytic--3f3ae0da-3005-42d7-afa3-8eaa8da3f700","name":"Analytic 0494","description":"Detects exploitation of authentication daemons or PAM modules. Defender perspective includes failed or anomalous PAM authentications, abnormal segfaults in authentication services, and exploitation attempts followed by successful unauthorized logins. Correlation identifies memory corruption, replay attempts, and privilege escalation tied to credential services.","url":"https://attack.mitre.org/detectionstrategies/DET0174#AN0494","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve: Suspicious binaries or scripts interacting with authentication binaries (sshd, gdm, login)","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"NSM:Connections","channel":"Repeated failed authentication attempts or replay patterns","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"nsm-connections"}],"mutable_elements":[{"field":"AuthServiceList","description":"List of monitored authentication services (e.g., sshd, gdm, PAM modules)."},{"field":"FailureThreshold","description":"Number of failed authentications within a window before escalating to replay suspicion."}],"live":true,"detection_strategies":["DET0174"],"techniques":["T1212"]},{"id":"AN0495","stix_id":"x-mitre-analytic--bb339113-e807-45fe-99c4-ed8348e51b36","name":"Analytic 0495","description":"Detects exploitation attempts against macOS authentication frameworks such as OpenDirectory or Keychain. Defender perspective includes abnormal crashes in opendirectoryd, unauthorized Keychain API usage, and unusual sudo or login events. Correlation links unexpected process behavior with credential access anomalies.","url":"https://attack.mitre.org/detectionstrategies/DET0174#AN0495","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"opendirectoryd crashes or abnormal authentication errors","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"execve: Processes unexpectedly invoking Keychain or authentication APIs","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"WatchedAPIs","description":"List of authentication and Keychain-related APIs to monitor for unauthorized access."},{"field":"CrashCorrelationWindow","description":"Time window for correlating authentication service crashes with subsequent suspicious access."}],"live":true,"detection_strategies":["DET0174"],"techniques":["T1212"]},{"id":"AN0496","stix_id":"x-mitre-analytic--0b8b8557-0393-4c63-963f-e5a3b5cc6ad8","name":"Analytic 0496","description":"Detects exploitation of vulnerabilities in cloud identity providers (IdPs) such as Azure AD or Okta for credential access. Defender perspective includes anomalous token creation or renewal, authentication bypass events, and API abuse to mint unauthorized tokens. Correlation highlights exploitation attempts tied to absent or inconsistent audit logs.","url":"https://attack.mitre.org/detectionstrategies/DET0174#AN0496","platforms":["Identity Provider"],"log_source_references":[{"name":"azure:signinlogs","channel":"TokenIssued, TokenRenewed: Unexpected or anomalous token issuance events","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"azure-signinlogs"},{"name":"m365:unified","channel":"ConsentGranted: Abuse of application integrations to mint tokens bypassing MFA","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"m365-unified"}],"mutable_elements":[{"field":"TokenAnomalyThreshold","description":"Threshold for anomalous token creation or renewal before alerting."},{"field":"MonitoredAppIntegrations","description":"Applications with privileged access that should be tightly monitored for misuse."}],"live":true,"detection_strategies":["DET0174"],"techniques":["T1212"]}],"live":true,"version":"1.0","techniques":["T1212"]}],"sigma_rules":[{"id":"1edd77db-0669-4fef-9598-165bda82826d","title":"Guacamole Two Users Sharing Session Anomaly","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2020-07-03","modified":"2021-11-27","description":"Detects suspicious session with two users present","references":["https://research.checkpoint.com/2020/apache-guacamole-rce/"],"logsource":{"product":"linux","service":"guacamole"},"tags":["attack.credential-access","attack.t1212"],"path":"rules/linux/builtin/guacamole/lnx_guacamole_susp_guacamole.yml","techniques":["T1212"],"cves":[]},{"id":"440a56bf-7873-4439-940a-1c8a671073c2","title":"GALLIUM IOCs","author":"Tim Burrell","status":"test","level":"high","date":"2020-02-07","modified":"2024-11-23","description":"Detects artifacts associated with GALLIUM cyber espionage group as reported by Microsoft Threat Intelligence Center in the December 2019 report.","references":["https://www.microsoft.com/security/blog/2019/12/12/gallium-targeting-global-telecom/","https://github.com/Azure/Azure-Sentinel/blob/a02ce85c96f162de6f8cc06f07a53b6525f0ff7f/Solutions/Legacy%20IOC%20based%20Threat%20Protection/Analytic%20Rules/GalliumIOCs.yaml"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.command-and-control","attack.t1212","attack.t1071","attack.g0093","detection.emerging-threats"],"path":"rules-emerging-threats/2020/TA/GALLIUM/proc_creation_win_apt_gallium_iocs.yml","techniques":["T1212","T1071"],"cves":[]},{"id":"48d91a3a-2363-43ba-a456-ca71ac3da5c2","title":"Audit CVE Event","author":"Florian Roth (Nextron Systems), Zach Mathis","status":"test","level":"critical","date":"2020-01-15","modified":"2022-10-22","description":"Detects events generated by user-mode applications when they call the CveEventWrite API when a known vulnerability is trying to be exploited.\nMS started using this log in Jan. 2020 with CVE-2020-0601 (a Windows CryptoAPI vulnerability.\nUnfortunately, that is about the only instance of CVEs being written to this log.\n","references":["https://twitter.com/VM_vivisector/status/1217190929330655232","https://twitter.com/DidierStevens/status/1217533958096924676","https://twitter.com/FlemmingRiis/status/1217147415482060800","https://www.youtube.com/watch?v=ebmW42YYveI","https://nullsec.us/windows-event-log-audit-cve/"],"logsource":{"product":"windows","service":"application"},"tags":["attack.execution","attack.stealth","attack.t1203","attack.privilege-escalation","attack.t1068","attack.t1211","attack.credential-access","attack.t1212","attack.lateral-movement","attack.t1210","attack.impact","attack.t1499.004"],"path":"rules/windows/builtin/application/microsoft-windows_audit_cve/win_audit_cve.yml","techniques":["T1203","T1068","T1211","T1212","T1210","T1499.004"],"cves":[]},{"id":"bb76d96b-821c-47cf-944b-7ce377864492","title":"Suspicious NTLM Authentication on the Printer Spooler Service","author":"Elastic (idea), Tobias Michalski (Nextron Systems)","status":"test","level":"high","date":"2022-05-04","modified":"2023-02-09","description":"Detects a privilege elevation attempt by coercing NTLM authentication on the Printer Spooler service","references":["https://twitter.com/med0x2e/status/1520402518685200384","https://github.com/elastic/detection-rules/blob/dd224fb3f81d0b4bf8593c5f02a029d647ba2b2d/rules/windows/credential_access_relay_ntlm_auth_via_http_spoolss.toml"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.credential-access","attack.t1212"],"path":"rules/windows/process_creation/proc_creation_win_rundll32_ntlmrelay.yml","techniques":["T1212"],"cves":[]},{"id":"f7644214-0eb0-4ace-9455-331ec4c09253","title":"Kerberos Manipulation","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2017-02-10","modified":"2024-01-16","description":"Detects failed Kerberos TGT issue operation. This can be a sign of manipulations of TGT messages by an attacker.","references":["https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4771"],"logsource":{"product":"windows","service":"security"},"tags":["attack.credential-access","attack.t1212"],"path":"rules/windows/builtin/security/win_security_susp_kerberos_manipulation.yml","techniques":["T1212"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2025-48928","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-48927","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2024-53704","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2022-22948","state":"mapped","mapping_types":["primary_impact"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}