Cross-source coverage

T1589.001 / ATT&CK

Gather Victim Identity Information: Credentials

3 rules across 2 sources.

From MITRE ATT&CK 19.2

Adversaries may gather credentials that can be used during targeting. Account credentials gathered by adversaries may be those directly associated with the target victim organization or attempt to take advantage of the tendency for users to use the same passwords across personal and business accounts.

Adversaries may gather credentials from potential victims in various ways, such as direct elicitation via Phishing for Information. Adversaries may also compromise sites then add malicious content designed to collect website authentication cookies from visitors. Where multi-factor authentication (MFA) based on out-of-band communications is in use, adversaries may compromise a service provider to gain access to MFA codes and one-time passwords (OTP).

Credential information may also be exposed to adversaries via leaks to online or other accessible data sets (ex: Search Engines, breach dumps, code repositories, etc.). Adversaries may purchase credentials from dark web markets, such as Russian Market and 2easy, or through access to Telegram channels that distribute logs from infostealer malware.

Gathering this information may reveal opportunities for other forms of reconnaissance (ex: Search Open Websites/Domains or Phishing for Information), establishing operational resources (ex: Compromise Accounts), and/or initial access (ex: External Remote Services or Valid Accounts).

Tactics
Reconnaissance
Platforms
PRE
Telemetry

How MITRE says to detect it DET0813

Detection of Credentials

PRE Analytic 1945

Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.


splunk/security_content

2 rules
Detection Severity Format
Linux Medusa Rootkit Undefined SPL
Windows Gather Victim Identity SAM Info Undefined SPL

Wazuh Core Ruleset

1 rule
Detection Severity Format
MS Graph message: A user's credentials were compromised or stolen. This is a true positive alert. Critical Wazuh XML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.