Terminology Index

Glossary

1801 terms

Open concept maps

Showing 449-480 of 1801 terms

C
32

Credential Access

The attacker objective and tactic of stealing valid credentials, passwords, hashes, tokens, or keys, to authenticate as legitimate users. With stolen credentials, attackers move and act while looking like normal activity.

Credential access is a pivotal stage in most intrusions: once attackers hold valid credentials they can move laterally, escalate privilege, and access data while blending in, which makes detection harder. Techniques include dumping credentials from memory, capturing them, cracking hashes, and phishing. As a MITRE ATT&CK tactic, it is a high-priority focus for detection because it underpins so much follow-on activity.

Introduced in: Threat Landscape and Attacker Thinking

Examples

  • Dumping credentials from a compromised host to reuse elsewhere.
  • Phishing a user's password to log in as them.
  • Stealing a session token to impersonate an authenticated user.

No related terms linked yet.