Compliance Node Overview
MITRE ATT&CK T1555.005 (Password Managers) is an Enterprise Credential Access sub-technique of T1555 (Credentials from Password Stores). Adversaries may acquire user credentials from third-party password managers. Password managers are applications designed to store user credentials, normally in an encrypted database. Credentials are typically accessible after a user provides a master password that unlocks the database. After the database is unlocked, these credentials may be copied to memory. These databases can be stored as files on disk. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1051 Update Software, M1018 User Account Management, M1017 User Training, M1054 Software Configuration, M1027 Password Policies. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-06, AC-20, CA-07, CM-02, CM-03, CM-06.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1555/005/
SHA-256 integrity: 4635c0faacb1d1628c1bb686adb05189f7cebfdfdf65a516f9f6f96b678bc295
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1555.005: Password Managers (https://attack.mitre.org/techniques/T1555/005/)
- MITRE ATT&CK Tactic TA0006: Credential Access (https://attack.mitre.org/tactics/TA0006/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access