Compliance Node Overview
MITRE ATT&CK T1558.005 (Ccache Files) is an Enterprise Credential Access sub-technique of T1558 (Steal or Forge Kerberos Tickets). Adversaries may attempt to steal Kerberos tickets stored in credential cache files (or ccache). These files are used for short term storage of a user's active session credentials. The ccache file is created upon user authentication and allows for access to multiple services without the user having to re-enter credentials. The /etc/krb5.conf configuration file and the KRB5CCNAME environment variable are used to set the storage location for ccache entries. Affected platforms: Linux, macOS. MITRE-documented mitigations include M1047 Audit, M1043 Credential Access Protection. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, AC-16, AC-17, AC-18, AC-19.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1558/005/
SHA-256 integrity: 1705b9d74065a8c4e295dd326599a191a94d109b98ed9dac8439000baa8e1776
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1558.005: Ccache Files (https://attack.mitre.org/techniques/T1558/005/)
- MITRE ATT&CK Tactic TA0006: Credential Access (https://attack.mitre.org/tactics/TA0006/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.