What MITRE ATT&CK T1555.006: Cloud Secrets Management Stores (Enterprise Tactic TA0006 - Credential Access) requires
MITRE ATT&CK T1555.006 (Cloud Secrets Management Stores) is an Enterprise Credential Access sub-technique of T1555 (Credentials from Password Stores). Adversaries may acquire credentials from cloud-native secret management solutions such as AWS Secrets Manager, GCP Secret Manager, Azure Key Vault, and Terraform Vault. Secrets managers support the secure centralized management of passwords, API keys, and other credential material. Where secrets managers are in use, cloud services can dynamically acquire credentials via API requests rather than accessing secrets insecurely stored in plain text files or environment variables. Affected platforms: IaaS. MITRE-documented mitigations include M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-06, AC-20, CA-07, CM-03, CM-07, IA-05.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1555/006/
SHA-256 integrity: 46982723ecba4e24aeb8c63c9df549de5d8517edaa30aa53d4570bcc4fa064ae
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1555.006: Cloud Secrets Management Stores (https://attack.mitre.org/techniques/T1555/006/)
- MITRE ATT&CK Tactic TA0006: Credential Access (https://attack.mitre.org/tactics/TA0006/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access