FORENSIA

ATT&CK · T1550

Use Alternate Authentication Material

Tactics: lateral-movement

About

Adversaries may use alternate authentication material, such as password hashes, Kerberos tickets, and application access tokens, in order to move laterally within an environment and bypass normal system access controls. Authentication processes generally require a valid identity (e.g., username) along with one or more authentication factors (e.g., password, pin, physical smart card, token generator, etc.). Alternate authentication material is legitimately generated by systems after a user or application successfully authenticates by providing a valid identity and the required authentication factor(s). Alternate authentication material may also be generated during the identity creation process. Caching alternate authentication material allows the system to verify an identity has successfully authenticated without asking the user to reenter authentication factor(s). Because the alternate authentication must be maintained by the system—either in memory or on disk—it may be at risk of being stolen through Credential Access techniques. By stealing alternate authentication material, adversaries are able to bypass system access controls and authenticate to systems without knowing the plaintext password or any additional authentication factors.

Platforms: Containers, IaaS, Identity Provider, Linux, Office Suite, SaaS, WindowsMITRE ATT&CK ↗

Used by actors

0 known groups

No mapped actors.

Software

1 malware/tools implement this

FoggyWeb

Corpus indicators tagged with this technique

36 indicators in the corpus carry T1550.

IndicatorTypeFamilySevSrc
6894a51278ec89118276c2dd2dc36e6f9ea2790ahashphishing802
febb622cd9eeb5c8860dcef4cbfd4b74hashphishing802
fcd1b654a0b3e8f85ca7cfdafe494d4bmd5phishing761
http://45.207.216.55:8084/slturl751
http://panel.securehubcloud.com/loginurlphishing752
http://91.215.85.103/pay_or_leak/instructure_affected_schools_list.txturlphishing754
41.128.0.142ipphishing701
jumpast.esdomainphishing651
buenne.dedomainphishing651
enerdizerandtron.dedomainphishing651
ihrsupportcenter.dedomainphishing651
rundwasser.dedomainphishing651
sonnenbrillenspot.dedomainphishing651
dwbud.vilaribit.comdomainphishing651
abal.mydomainphishing651
starwellmedia.comdomainphishing651
aabiz.dedomainphishing651
aspireglobal.ltddomainphishing651
dufllot.sbsdomainphishing651
espaciocf.dedomainphishing651
ilersls.orgdomainphishing651
aaalen.dedomainphishing651
smartcontrolengineer.comdomainphishing651
trisrnareprjdocz.comdomainphishing651
razen.onlinedomainphishing651
theoceanac.onlinedomainphishing651
crm-technik.dedomainphishing651
klenpare.comdomainphishing651
uvarnix.cfddomainphishing651
xavon.sbsdomainphishing651

Showing the top 30 by severity of 36.