{"id":"T1558.005","name":"Ccache Files","url":"https://attack.mitre.org/techniques/T1558/005","tactics":["credential-access"],"platforms":["Linux","macOS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0024","stix_id":"x-mitre-detection-strategy--5c4334d0-cda0-4372-8572-fe2a109d39cb","name":"Detect Kerberos Ccache File Theft or Abuse (T1558.005)","url":"https://attack.mitre.org/detectionstrategies/DET0024","analytics":[{"id":"AN0069","stix_id":"x-mitre-analytic--3651d7d0-dfc7-4b36-aaf2-4eb0eb39167d","name":"Analytic 0069","description":"Detects unauthorized access, copying, or modification of Kerberos ccache files (krb5cc_%UID% or krb5.ccache) in /tmp or custom paths defined by KRB5CCNAME. Correlates file access with suspicious processes (e.g., credential dumping tools) and subsequent anomalous Kerberos authentication requests from non-standard processes.","url":"https://attack.mitre.org/detectionstrategies/DET0024#AN0069","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"open: File access attempt on /tmp/krb5cc_* or /tmp/krb5.ccache","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"execve: Execution of klist, kinit, or tools interacting with ccache outside normal user context","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"CcachePathBaseline","description":"Expected directories or environment variable (KRB5CCNAME) paths for ccache files in the environment."},{"field":"AllowedProcesses","description":"Baseline list of processes legitimately interacting with ccache (e.g., klist, kinit)."},{"field":"TimeWindow","description":"Correlation window for linking file access, process execution, and Kerberos requests."}],"live":true,"detection_strategies":["DET0024"],"techniques":["T1558.005"]},{"id":"AN0070","stix_id":"x-mitre-analytic--2a9d296d-6b36-42de-870c-9d851c0471ed","name":"Analytic 0070","description":"Detects abnormal interaction with memory-based Kerberos ccache (API:{uuid}) or file-based overrides. Focus on processes attempting to enumerate or extract Kerberos tickets outside of built-in utilities. Detects use of open-source tools (e.g., Bifrost, modified Mimikatz ports) that interact with the Kerberos framework APIs.","url":"https://attack.mitre.org/detectionstrategies/DET0024#AN0070","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Kerberos framework calls to API:{uuid} cache outside normal process lineage","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"Execution of non-standard binaries accessing Kerberos APIs","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"KerberosAPIProcessBaseline","description":"Expected processes using the Kerberos framework (e.g., loginwindow, kinit)."},{"field":"SuspiciousBinaryList","description":"List of tools or binaries not normally expected to query Kerberos ccache entries."},{"field":"TimeWindow","description":"Window to link suspicious process activity with Kerberos authentication anomalies."}],"live":true,"detection_strategies":["DET0024"],"techniques":["T1558.005"]}],"live":true,"version":"1.0","techniques":["T1558.005"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}