Credential Access
Adversaries steal credentials to move freely through your environment as legitimate users. ManySignal detects credential theft at the moment it occurs — before those credentials are weaponised for lateral movement or data exfiltration.
Coverage
- Techniques covered
- 17
- Detection rules
- 61
- Avg. detection latency
- < 3 min
Threat context
How adversaries steal credentials
Credential theft is the pivot point between initial compromise and full attack execution. Once an adversary has valid credentials — whether a password, a session token, or an API key — they can move laterally, access sensitive data, and establish persistence without triggering the signature-based detections designed for malware. This is why 80%+ of cloud breaches involve credential-based attacks.
Modern credential theft is increasingly targeting the identity layer directly: MFA fatigue bypasses the second factor through social engineering; AiTM proxies capture session tokens post-authentication; Golden SAML forges authentication assertions using stolen cryptographic keys. Defence requires behavioural analytics, not just signature matching.
Techniques
Credential Access techniques ManySignal detects
Brute Force
Password spraying, credential stuffing, and targeted brute force attacks.
OS Credential Dumping
LSASS dump, DCSync, SAM extraction, and /etc/shadow access.
Steal Web Session Cookie
AiTM session token theft to bypass MFA post-authentication.
MFA Request Generation
Push flood attacks to fatigue users into approving MFA without legitimate cause.
Unsecured Credentials
Credentials hardcoded in code, .env files, S3 buckets, or CI/CD environment variables.
Credentials from Password Stores
Extraction from browser credential stores, macOS Keychain, or Windows Credential Manager.
Forge Web Credentials
SAML assertion forgery (Golden SAML) using stolen AD FS signing certificates.
Credential Access: frequently asked questions
What is ATT&CK Credential Access (TA0006)?
Credential Access covers the techniques adversaries use to steal credentials — passwords, hashes, tokens, session cookies, API keys, and certificates. Stolen credentials enable subsequent lateral movement and persistence while appearing as legitimate user activity.
Which credential access technique is most common in cloud breaches?
MFA fatigue (T1621) and AiTM session token theft (T1539) are the fastest-growing techniques, specifically because they bypass traditional MFA controls. Credential dumping (T1003) remains dominant in Windows environments where attackers gain endpoint access.
How does ManySignal detect credential theft without endpoint access?
Many credential theft techniques leave identity-layer indicators even without endpoint telemetry. MFA fatigue creates an abnormal push volume pattern. Session token theft shows as sessions accessed from new IPs. Credential stuffing generates characteristic failure-then-success patterns on authentication endpoints.
Can ManySignal detect secrets exposed in GitHub repositories?
Yes. Via the GitHub integration, ManySignal ingests Secret Scanning alerts and correlates them with subsequent API calls using those credentials. A detected leaked secret followed by an API call using that secret is a high-confidence indicator of exploitation.
Detect credential theft before it becomes a breach
ManySignal correlates authentication anomalies, endpoint telemetry, and threat intelligence to surface credential theft within minutes.