What MITRE ATT&CK T1212: Exploitation for Credential Access (Enterprise Tactic TA0006 - Credential Access) requires
MITRE ATT&CK T1212 (Exploitation for Credential Access) is an Enterprise Credential Access technique. Adversaries may exploit software vulnerabilities in an attempt to collect credentials. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Credentialing and authentication mechanisms may be targeted for exploitation by adversaries as a means to gain access to useful credentials or circumvent the process to gain authenticated access to systems. Affected platforms: Linux, Windows, macOS, Identity Provider. MITRE-documented mitigations include M1050 Exploit Protection, M1051 Update Software, M1013 Application Developer Guidance, M1019 Threat Intelligence Program, M1048 Application Isolation and Sandboxing. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-04, AC-06, CA-07, CM-02, CM-06, CM-08, IA-02.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1212/
SHA-256 integrity: 94c7640834fdb49eb342c51389957e6d0427ea76f36ccfa492538b7f8af87761
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1212: Exploitation for Credential Access (https://attack.mitre.org/techniques/T1212/)
- MITRE ATT&CK Tactic TA0006: Credential Access (https://attack.mitre.org/tactics/TA0006/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access