Credential Access · Learn

What is credential access?

Credential access is the phase where an attacker collects the passwords, hashes, and tickets that let them log in as other users and move across a network. Here is what it covers and where credentials hide.

Credential Access · LearnAll services
TL;DR

Credential access is the attacker phase of stealing account credentials, passwords, password hashes, Kerberos tickets, and API keys, to authenticate as legitimate users and spread through an environment. Credentials are harvested from memory (LSASS), registry hives (SAM, LSA secrets), disk (config files, /etc/shadow), the network (LLMNR poisoning), and applications (browsers, Credential Manager). It is the engine behind lateral movement, because a reused credential turns one host into many.

By John Dill, Red Team Lead, SecureLayer7Updated

What credential access is

Once an attacker has a foothold, they rarely have the credentials they ultimately want. Credential access is the work of harvesting more: every password, hash, ticket, or key they can pull from the machine and the network.

Those credentials are the currency of an intrusion. With them the attacker authenticates as real users, so their activity blends in and they can reach systems their initial foothold never could.

Where credentials hide

Credentials live in many places, each with its own page:

What attackers do with credentials

Harvested credentials feed straight into lateral movement. Cleartext passwords are reused directly; hashes are either cracked with Hashcat or John, or used as-is via Pass-the-Hash; tickets are replayed with Pass-the-Ticket.

The loop, dump on host A, reuse on host B, dump host B, is what carries an attacker to a Domain Controller.

References

  1. [1]MITRE ATT&CK: Credential Access (TA0006)(MITRE)
  2. [2]MITRE ATT&CK: OS Credential Dumping (T1003)(MITRE)
  3. [3]NIST SP 800-63B Digital Identity Guidelines(NIST)
Related terms

Common questions

Credential access, asked often

Want your environment tested for exposed credentials?

Scope an engagement

Find the exposed credentials before an attacker does.

Our internal and network penetration tests hunt the credentials an intruder would, in memory, registry hives, config files, and on the wire, then show your team exactly where each one was exposed and how to close it. Free re-test included.

See all services30-min scoping call, fixed-price proposal in 48 hours.