FORENSIA

ATT&CK · T1555.004 · sub-technique

Windows Credential Manager

Tactics: credential-access

About

Adversaries may acquire credentials from the Windows Credential Manager. The Credential Manager stores credentials for signing into websites, applications, and/or devices that request authentication through NTLM or Kerberos in Credential Lockers (previously known as Windows Vaults). The Windows Credential Manager separates website credentials from application or network credentials in two lockers. As part of Credentials from Web Browsers, Internet Explorer and Microsoft Edge website credentials are managed by the Credential Manager and are stored in the Web Credentials locker. Application and network credentials are stored in the Windows Credentials locker. Credential Lockers store credentials in encrypted `.vcrd` files, located under `%Systemdrive%\Users\\[Username]\AppData\Local\Microsoft\\[Vault/Credentials]\`. The encryption key can be found in a file named <code>Policy.vpol</code>, typically located in the same folder as the credentials. Adversaries may list credentials managed by the Windows Credential Manager through several mechanisms. <code>vaultcmd.exe</code> is a native Windows executable that can be used to enumerate credentials stored in the Credential Locker through a command-line interface. Adversaries may also gather credentials by directly reading files located inside of the Credential Lockers. Windows APIs, such as <code>CredEnumerateA</code>, may also be absued to list credentials managed by the Credential Manager. Adversaries may also obtain credentials from credential backups. Credential backups and restorations may be performed by running <code>rundll32.exe keymgr.dll KRShowKeyMgr</code> then selecting the “Back up...” button on the “Stored User Names and Passwords” GUI. Password recovery tools may also obtain plain text passwords from the Credential Manager.

Used by actors

4 known groups

Software

9 malware/tools implement this

MimikatzPowerSploitROKRATLaZagneValakKGH_SPYRainyDayLizarSILENTTRINITY

Corpus indicators tagged with this technique

94 indicators in the corpus carry T1555.004.

IndicatorTypeFamilySevSrc
340820f7f4c97e3a2477bc99acf746e13b2c92719ebf5c9947a62eef7ec0dddbsha256phishing801
91b9381d19b2e6a2db5cc0307167979b502731cb3fb50da684479e9ed35261aahashphishing802
35813f4401d3ad77b618275473a556eb47bfa6f4b7439dd8943b19f81aa7252ehashphishing802
cff8b04f2c8ed63d37fd393ad23652a8b818e80b03851d7c1bd5842963a03348sha256phishing801
6cf9f7b2aa456a0b438600588df869b38d8007e28f01fa96022f9d8059f120b0hashphishing802
339907b44f161f57ff30819f422c552382ff437b3ae437463b4222cfe86bd943hashphishing802
4c0d9b802c075be79e9edb52d88f8dd72e6904f5c58267213745818470945c78hashphishing802
734699773e53d995f20d485eb61261033d9d00b4332b39ca26071bcd60cd352fhashphishing802
bb10adac5b0124efedfe71102c1d5638135ec9e1cde8c8cb3353c5ed91bb9f81hashphishing802
e8e7faa5e76dc773ffb1a7a6be36a47cc84e3ed45b928859b570332757cdb6cbsha256phishing801
2812e0847d472cb8870c94f463331dbe53b84135132b9bf5f6d84c2382be628fhashphishing802
4f7a8c3d2e1b5f9071a6b2c8d4e3f50a92b1c7d6e8f4a30b5c2d9e1f7a6b8c4dhashphishing802
c935808147f0236c81483d7bbeda4b9d602f3595d5d4057f8115d39e222d1c4bhashphishing802
e1bf1b29e6fa3525d7f32f429290a88d6ea2890e61c06574b8ff6372aa5d0667hashphishing802
d3ebce2f05fe91a8260e87fd11a6ea17c156703d081b3f91d9bbe5fd6aeedc10hashphishing802
62761f38ed194c59abe15c49f09f0ebc431ac852c965180c9327ed84d3a454fbhashphishing802
808e7154b7af2bc7a4b28d577297c55f77221c355191cbe00f9f1810b6d4a619hashphishing802
a2b9a769df84d9d3a4694bb0252a2c6a5e5f5d1a85a04565362737092bbb3a86hashphishing802
d5e9288693aa745dc89368deac677e7ea1ec81e663283af30838cdae189b7a7ehashphishing802
52886aab179f26421678ff23af1b0fabf0a17ffbb534369cdbbac8008cbed8e7hashphishing802
87cb13512daff0f4e1783a59af449336b6e010e4sha1phishing781
bea391c7ef1665bc33712deee1109812fc606cc6sha1phishing781
6eaf8f8cfc9161c6a287d0a1ce8ab436d14cfcadsha1phishing781
1bbf1e83eea55e70d59f0d633789011emd5phishing761
0b8af4afd26175ba818c0fdb4622bf14md5phishing761
536dd0b0f6dff75dc01869df9809df61md5phishing761
7dd16d1018865e5e817c418f87e6be00md5phishing761
2fba9ec34fdf4b1584dd9c69b9ec9393md5phishing761
4e885b1a0c1d0636e940b4af20fdc8dbmd5phishing761
23.137.105.75ipphishing701

Showing the top 30 by severity of 94.