What MITRE ATT&CK T1555: Credentials from Password Stores (Enterprise Tactic TA0006 - Credential Access) requires
MITRE ATT&CK T1555 covers adversary access to credentials stored in browsers, password managers, and OS credential stores. Sub-techniques include Keychain (T1555.001), Securityd Memory (T1555.002), Credentials from Web Browsers (T1555.003), Windows Credential Manager (T1555.004), and Password Managers (T1555.005). Browser credential theft is a primary objective of modern infostealers (RedLine, Vidar, LummaC2, StealC). Compliance obligations include enterprise password manager deployment, SSO adoption, and browser hardening required under NIS2 Article 21, DORA Article 9, and ISO 27001 A.5.17.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1555/
SHA-256 integrity: 2736268f47fc6b5252b2409d1e12bbcfdbbc4b623b25e2ae4d5c666418898f48
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1555: Credentials from Password Stores (https://attack.mitre.org/techniques/T1555/) with sub-techniques for Keychain, browsers, Windows Credential Manager, password managers
- NIST SP 800-53 Rev 5: IA-5 (Authenticator Management), SC-28 (Protection of Information at Rest)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access