What MITRE ATT&CK T1555.004: Windows Credential Manager (Enterprise Tactic TA0006 - Credential Access) requires
MITRE ATT&CK T1555.004 (Windows Credential Manager) is an Enterprise Credential Access sub-technique of T1555 (Credentials from Password Stores). Adversaries may acquire credentials from the Windows Credential Manager. The Credential Manager stores credentials for signing into websites, applications, and/or devices that request authentication through NTLM or Kerberos in Credential Lockers (previously known as Windows Vaults). The Windows Credential Manager separates website credentials from application or network credentials in two lockers. Affected platforms: Windows. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-03, AC-06, AC-20, CA-07, CM-02, CM-03, CM-06, CM-07.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1555/004/
SHA-256 integrity: f7767b73384afaeefbe90d5526012ecef0d045afbadb9b82915f6b16ee3ce252
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1555.004: Windows Credential Manager (https://attack.mitre.org/techniques/T1555/004/)
- MITRE ATT&CK Tactic TA0006: Credential Access (https://attack.mitre.org/tactics/TA0006/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.