{"id":"T1555.005","name":"Password Managers","url":"https://attack.mitre.org/techniques/T1555/005","tactics":["credential-access"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0597","stix_id":"x-mitre-detection-strategy--a5600691-be46-424a-b8ef-a2c9159da49a","name":"Detect Unauthorized Access to Password Managers","url":"https://attack.mitre.org/detectionstrategies/DET0597","analytics":[{"id":"AN1641","stix_id":"x-mitre-analytic--18ab8a54-68bc-4d43-884d-2b9284eb723e","name":"Analytic 1641","description":"Detection of suspicious access to password manager processes (KeePass, 1Password, LastPass, Bitwarden) through abnormal process injection, memory reads, or command-line usage of vault-related DLLs. Correlates process creation with OS API calls and file access to vault databases (.kdbx, .opvault, .ldb).","url":"https://attack.mitre.org/detectionstrategies/DET0597#AN1641","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=10","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=15","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"PasswordManagerBinaries","description":"List of monitored binaries and file formats for password managers in use (e.g., KeePass, 1Password, Bitwarden, LastPass)."},{"field":"TimeWindow","description":"Window to correlate process creation, API access, and file reads indicative of credential extraction."},{"field":"UserContext","description":"Filter for administrative accounts vs. expected users of password managers."}],"live":true,"detection_strategies":["DET0597"],"techniques":["T1555.005"]},{"id":"AN1642","stix_id":"x-mitre-analytic--93fd8592-d8ce-4b5e-b095-71cd66062298","name":"Analytic 1642","description":"Suspicious access to password manager vaults (KeePassXC, gnome-keyring, pass) via memory scraping or unauthorized file reads. Detects unusual command execution involving gdb/strace attached to password manager processes.","url":"https://attack.mitre.org/detectionstrategies/DET0597#AN1642","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"open/read on ~/.local/share/keepassxc/* OR ~/.password-store/*","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"ptrace","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"VaultFilePaths","description":"Linux paths to monitor for vault database files (KeePassXC, pass, gnome-keyring)."},{"field":"TimeWindow","description":"Correlation interval to detect multiple suspicious access events."}],"live":true,"detection_strategies":["DET0597"],"techniques":["T1555.005"]},{"id":"AN1643","stix_id":"x-mitre-analytic--de1d4807-fcb5-4112-b310-ea0c4df45af2","name":"Analytic 1643","description":"Detection of password manager database access (1Password .opvault, LastPass caches, KeePass .kdbx) outside expected parent processes. Identifies memory scraping attempts via suspicious API calls or tools attaching to password manager processes.","url":"https://attack.mitre.org/detectionstrategies/DET0597#AN1643","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"security OR injection attempts into 1Password OR LastPass","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"*.opvault OR *.ldb OR *.kdbx","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"unexpected memory inspection","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"VaultFileExtensions","description":"Password manager file extensions (.opvault, .kdbx, .ldb) to monitor for anomalous access."},{"field":"ParentProcessWhitelist","description":"Expected parent processes that normally access password manager files, for filtering false positives."}],"live":true,"detection_strategies":["DET0597"],"techniques":["T1555.005"]}],"live":true,"version":"1.0","techniques":["T1555.005"]}],"sigma_rules":[{"id":"77564cc2-7382-438b-a7f6-395c2ae53b9a","title":"Remote Thread Created In KeePass.EXE","author":"Timon Hackenjos","status":"test","level":"high","date":"2022-04-22","modified":"2023-05-05","description":"Detects remote thread creation in \"KeePass.exe\" which could indicates potential password dumping activity","references":["https://www.cisa.gov/uscert/ncas/alerts/aa20-259a","https://github.com/denandz/KeeFarce","https://github.com/GhostPack/KeeThief"],"logsource":{"product":"windows","category":"create_remote_thread"},"tags":["attack.credential-access","attack.t1555.005"],"path":"rules/windows/create_remote_thread/create_remote_thread_win_keepass.yml","techniques":["T1555.005"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}