What MITRE ATLAS OS Credential Dumping (AML.T0090) - Adversarial use of OS Credential Dumping as adapted in MITRE ATT&CK T1003 requires
This node addresses MITRE ATLAS technique AML.T0090 (OS Credential Dumping). Adversaries may extract credentials from OS caches, application memory, or other sources on a compromised system. Credentials are often in the form of a hash or clear text, and can include usernames and passwords, application tokens, or other authentication keys. Credentials can be used to perform Lateral Movement to access other AI services such as AI agents, LLMs, or AI inference APIs. Credentials could also give an adversary access to other software tools and data sources that are part of the AI DevOps lifecycle. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. ATT&CK reference: T1003 provides authoritative mitigation guidance for this technique class.
Pillar: AI Governance & Law · Authority: MITRE Corporation · Version: 1.0.1 · Last updated:
Primary source: https://raw.githubusercontent.com/mitre-atlas/atlas-data/main/dist/ATLAS.yaml
SHA-256 integrity: 8389d28b0bc86c8636d85c1be4e616d493012aa0f57240ac2b6be4c8ca7b760f
Primary Citations — 6 traced to source
- MITRE ATLAS - OS Credential Dumping (AML.T0090), https://raw.githubusercontent.com/mitre-atlas/atlas-data/main/dist/ATLAS.yaml#AML.T0090, AML.T0090 technique entry, 2026
- EU AI Act - Regulation (EU) 2024/1689 on Artificial Intelligence, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689, Article 15 (Accuracy, Robustness, Cybersecurity), 2024
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-atlas-os-credential-dumping.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-atlas-os-credential-dumping.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-atlas-os-credential-dumping
- Back to registry: Browse all 10,099 compliance nodes