kevmap

Techniques › T1212

T1212 Exploitation for Credential Access

credential access — Linux, Windows, macOS, Identity Provider · attack.mitre.org · JSON

1
MITRE detection strategy
4
analytics
5
Sigma rules tagged attack.t1212
4
KEV CVEs mapped here
<p>Adversaries may exploit software vulnerabilities in an attempt to collect credentials. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code.</p><p>Credentialing and authentication mechanisms may be targeted for exploitation by adversaries as a means to gain access to useful credentials or circumvent the process to gain authenticated access to systems. One example of this is MS14-068, which targets Kerberos and can be used to forge Kerberos tickets using domain user permissions. Another example of this is replay attacks, in which the adversary intercepts data packets sent between parties and then later replays these packets. If services don't properly validate authentication requests, these replayed packets may allow an adversary to impersonate one of the parties and gain unauthorized access or privileges.</p><p>Such exploitation has been demonstrated in cloud environments as well. For example, adversaries have exploited vulnerabilities in public cloud infrastructure that allowed for unintended authentication token creation and renewal.</p><p>Exploitation for credential access may also result in Privilege Escalation depending on the process targeted or credentials obtained.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

CVEVendor / productMapping typeStateAdded
CVE-2025-48928TeleMessage TM SGNL exploitation technique Mapped2025-07-01
CVE-2025-48927TeleMessage TM SGNL exploitation technique Mapped2025-07-01
CVE-2024-53704SonicWall SonicOS exploitation technique Mapped2025-02-18
CVE-2022-22948VMware vCenter Server primary impact Mapped2024-07-17

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1212

Author: Florian Roth (Nextron Systems) · 2020-07-03 (modified 2021-11-27) · logsource: product=linux service=guacamole · 1edd77db-0669-4fef-9598-165bda82826d
Detects suspicious session with two users present
Techniques: T1212
GALLIUM IOCs hightest
Author: Tim Burrell · 2020-02-07 (modified 2024-11-23) · logsource: product=windows category=process_creation · 440a56bf-7873-4439-940a-1c8a671073c2
Detects artifacts associated with GALLIUM cyber espionage group as reported by Microsoft Threat Intelligence Center in the December 2019 report.
Techniques: T1212T1071
Audit CVE Event criticaltest
Author: Florian Roth (Nextron Systems), Zach Mathis · 2020-01-15 (modified 2022-10-22) · logsource: product=windows service=application · 48d91a3a-2363-43ba-a456-ca71ac3da5c2
Detects events generated by user-mode applications when they call the CveEventWrite API when a known vulnerability is trying to be exploited. MS started using this log in Jan. 2020 with CVE-2020-0601 (a Windows CryptoAPI vulnerability. Unfortunately, that is about the only instance of CVEs being written to this log.
Author: Elastic (idea), Tobias Michalski (Nextron Systems) · 2022-05-04 (modified 2023-02-09) · logsource: product=windows category=process_creation · bb76d96b-821c-47cf-944b-7ce377864492
Detects a privilege elevation attempt by coercing NTLM authentication on the Printer Spooler service
Techniques: T1212
Author: Florian Roth (Nextron Systems) · 2017-02-10 (modified 2024-01-16) · logsource: product=windows service=security · f7644214-0eb0-4ace-9455-331ec4c09253
Detects failed Kerberos TGT issue operation. This can be a sign of manipulations of TGT messages by an attacker.
Techniques: T1212