Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0174 — Detection Strategy for Exploitation for Credential Access
DET0174

Detection Strategy for Exploitation for Credential Access

4 analytic(s) · 1 technique(s) detected

Analytics

4
AN0493 Analytic 0493
Windows

Detects adversary exploitation of authentication mechanisms or credential validation processes. Defender perspective includes forged Kerberos tickets (e.g., MS14-068), abnormal LSASS memory access, replayed authentication attempts, and unexpected crashes of authentication services. Multi-event correlation ties exploitation attempts to abnormal process creation, service instability, and suspicious authentication events.

WinEventLog:Security EventCode=4768, 4769, 4770 WinEventLog:Sysmon EventCode=10
[MonitoredAccounts] High-value accounts (e.g., Domain Admins) for anomalous ticket issuance or replay activity.
[ReplayDetectionWindow] Time window for correlating duplicate or replayed Kerberos authentications.
AN0494 Analytic 0494
Linux

Detects exploitation of authentication daemons or PAM modules. Defender perspective includes failed or anomalous PAM authentications, abnormal segfaults in authentication services, and exploitation attempts followed by successful unauthorized logins. Correlation identifies memory corruption, replay attempts, and privilege escalation tied to credential services.

auditd:SYSCALL execve: Suspicious binaries or scripts interacting with authentication binaries (sshd, gdm, login) NSM:Connections Repeated failed authentication attempts or replay patterns
[AuthServiceList] List of monitored authentication services (e.g., sshd, gdm, PAM modules).
[FailureThreshold] Number of failed authentications within a window before escalating to replay suspicion.
AN0495 Analytic 0495
macOS

Detects exploitation attempts against macOS authentication frameworks such as OpenDirectory or Keychain. Defender perspective includes abnormal crashes in opendirectoryd, unauthorized Keychain API usage, and unusual sudo or login events. Correlation links unexpected process behavior with credential access anomalies.

macos:unifiedlog opendirectoryd crashes or abnormal authentication errors macos:osquery execve: Processes unexpectedly invoking Keychain or authentication APIs
[WatchedAPIs] List of authentication and Keychain-related APIs to monitor for unauthorized access.
[CrashCorrelationWindow] Time window for correlating authentication service crashes with subsequent suspicious access.
AN0496 Analytic 0496
Identity Provider

Detects exploitation of vulnerabilities in cloud identity providers (IdPs) such as Azure AD or Okta for credential access. Defender perspective includes anomalous token creation or renewal, authentication bypass events, and API abuse to mint unauthorized tokens. Correlation highlights exploitation attempts tied to absent or inconsistent audit logs.

azure:signinlogs TokenIssued, TokenRenewed: Unexpected or anomalous token issuance events m365:unified ConsentGranted: Abuse of application integrations to mint tokens bypassing MFA
[TokenAnomalyThreshold] Threshold for anomalous token creation or renewal before alerting.
[MonitoredAppIntegrations] Applications with privileged access that should be tightly monitored for misuse.

Detected Techniques

1

Details

MITRE ID
DET0174
STIX ID
x-mitre-detection-strategy--13a856f3-66b2-4ab7-b73f-2a26e712e77f
Analytics
4
Techniques Detected
1
By Tactic
Credential Access
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.