{
  "node_id": "mitre-attack-t1110-004-credential-stuffing",
  "title": "MITRE ATT&CK T1110.004: Credential Stuffing (Enterprise Tactic TA0006 - Credential Access)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-05-25",
  "bluf": "MITRE ATT&CK T1110.004 (Credential Stuffing) is an Enterprise Credential Access sub-technique of T1110 (Brute Force). Adversaries may use credentials obtained from breach dumps of unrelated accounts to gain access to target accounts through credential overlap. Occasionally, large numbers of username and password pairs are dumped online when a website or service is compromised and the user account credentials accessed. The information may be useful to an adversary attempting to compromise accounts by taking advantage of the tendency for users to use the same passwords across personal and business accounts. Affected platforms: Windows, SaaS, IaaS, Linux, macOS, Containers, Network, Office Suite, Identity Provider. MITRE-documented mitigations include M1036 Account Use Policies, M1027 Password Policies, M1018 User Account Management, M1032 Multi-factor Authentication. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, AC-07, AC-20, CA-07, CM-02.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "mitre_d3fend"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-cybersecurity-framework-2-0",
    "iso-27001-2022",
    "nist-sp-800-53-r5",
    "cis-controls-v8",
    "mitre-attack-t1110-brute-force"
  ],
  "primary_citations_count": 7
}