Credential Access Detection Rules
The adversary is trying to steal account names and passwords. Credential Access consists of techniques for stealing credentials like account names and passwords. Techniques used to get credentials include keylogging or credential dumping. Using legitimate credentials can give adversaries access to systems, make them harder to detect, and provide the opportunity to create more accounts to help achieve their goals.
df00tech ships 126 production-ready detection rules mapped to the Credential Access tactic (TA0006). Each rule below includes copy-paste queries for Microsoft Sentinel (KQL), Splunk (SPL), Elastic (EQL), QRadar, Sumo Logic, Chronicle and LogScale, with data-source requirements, severity and false-positive guidance — free to use.
Unlock the full Pro package
Response playbooks, investigation guides and atomic tests for every technique — from £29/mo.
Credential Access detections (126)
- CVE-2017-7921 Hikvision Improper Authentication Exploitation (CVE-2017-7921)
- CVE-2019-19006 Sangoma FreePBX Remote Admin Authentication Bypass (CVE-2019-19006)
- CVE-2021-22681 Rockwell Automation Logix Controllers Insufficient Credential Protection (CVE-2021-22681)
- CVE-2021-26829 OpenPLC ScadaBR Cross-Site Scripting (XSS) Exploitation Detected
- CVE-2023-4346 KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout (CVE-2023-4346)
- CVE-2023-36424 CVE-2023-36424 - Microsoft Windows Out-of-Bounds Read Exploitation
- CVE-2024-21413 CVE-2024-21413: Microsoft Outlook RCE via Moniker Link (MonikerLink)
- CVE-2024-21887 Ivanti Connect Secure Authenticated Command Injection (CVE-2024-21887)
- CVE-2024-23897 CVE-2024-23897: Jenkins Arbitrary File Read via CLI Argument Parser (Pre-Auth RCE Chain)
- CVE-2024-27199 JetBrains TeamCity Relative Path Traversal (CVE-2024-27199)
- CVE-2024-43451 CVE-2024-43451: Windows NTLM Hash Disclosure via File Interaction
- CVE-2024-43468 CVE-2024-43468: Microsoft Configuration Manager SQL Injection Exploitation
- CVE-2024-57728 SimpleHelp Path Traversal Vulnerability (CVE-2024-57728)
- CVE-2025-6205 Dassault Systèmes DELMIA Apriso Missing Authorization (CVE-2025-6205)
- CVE-2025-8110 Gogs Path Traversal Vulnerability (CVE-2025-8110)
- CVE-2025-12480 Gladinet Triofox Improper Access Control Exploitation Detected
- CVE-2025-24054 Windows NTLM Credential Leak via File Download Interaction
- CVE-2025-40536 SolarWinds Web Help Desk Security Control Bypass (CVE-2025-40536)
- CVE-2025-48700 Zimbra Collaboration Suite XSS Exploitation (CVE-2025-48700)
- CVE-2025-58360 OSGeo GeoServer XXE Injection Exploitation Attempt
- CVE-2025-66376 Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Exploitation
- CVE-2025-68461 RoundCube Webmail Cross-Site Scripting (XSS) Exploitation Attempt
- CVE-2026-0257 Palo Alto Networks PAN-OS Authentication Bypass (CVE-2026-0257)
- CVE-2026-9082 Drupal Core SQL Injection Exploitation (CVE-2026-9082)
- CVE-2026-20127 Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass (CVE-2026-20127)
- CVE-2026-20128 Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format (CVE-2026-20128)
- CVE-2026-20133 Cisco Catalyst SD-WAN Manager Sensitive Information Exposure (CVE-2026-20133)
- CVE-2026-20262 Cisco Catalyst SD-WAN Manager Path Traversal Exploitation
- CVE-2026-20805 Microsoft Windows Information Disclosure (CVE-2026-20805)
- CVE-2026-21643 Fortinet FortiClient EMS SQL Injection Exploitation (CVE-2026-21643)
- CVE-2026-22769 Dell RecoverPoint for Virtual Machines (RP4VMs) Hard-coded Credentials Exploitation
- CVE-2026-23760 SmarterMail Authentication Bypass via Alternate Path or Channel (CVE-2026-23760)
- CVE-2026-24858 Fortinet Multiple Products Authentication Bypass via Alternate Path or Channel (CVE-2026-24858)
- CVE-2026-32966 Apache DolphinScheduler DataSource API Missing Authorization - Arbitrary Metadata Disclosure (CVE-2026-32966)
- CVE-2026-34926 Trend Micro Apex One Directory Traversal Exploitation (CVE-2026-34926)
- CVE-2026-35273 Oracle PeopleSoft PeopleTools Missing Authentication for Critical Function (CVE-2026-35273)
- CVE-2026-42208 BerriAI LiteLLM SQL Injection Exploitation (CVE-2026-42208)
- CVE-2026-42897 Microsoft Exchange Server Cross-Site Scripting (XSS) Exploitation
- CVE-2026-44935 Rancher Fleet Cross-Namespace Secret Disclosure via Unvalidated valuesFrom in Helm Deployer (CVE-2026-44935)
- CVE-2026-46817 Oracle E-Business Suite Improper Privilege Management Exploitation (CVE-2026-46817)
- CVE-2026-47410 PraisonAI Platform JWT Hardcoded Secret Key Token Forgery
- CVE-2026-47429 CVE-2026-47429: Vitest UI Server Arbitrary File Read and Execution
- CVE-2026-48282 CVE-2026-48282: Adobe ColdFusion Path Traversal Exploitation
- CVE-2026-48750 Incus exec-output Symlink Arbitrary File Write on Host (CVE-2026-48750)
- CVE-2026-50751 Check Point Security Gateway Improper Authentication (CVE-2026-50751)
- CVE-2026-54350 Budibase Anonymous NoSQL Operator Injection via Published-App Query Templates
- CVE-2026-54420 LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability
- CVE-2026-54782 CoreWCF SAML Token Signature Validation Authentication Bypass (CVE-2026-54782)
- CVE-2026-55166 CVE-2026-55166: Lemur ACME SSRF and IDOR Leading to AWS IAM/PKI Compromise
- CVE-2026-55255 Langflow IDOR: Unauthorized Access to Another User's Flow via /api/v1/responses
- CVE-2026-56155 Microsoft AD FS Insufficient Access Control Granularity Exploitation (CVE-2026-56155)
- CVE-2026-56266 Crawl4AI Docker API Multiple Critical Vulnerabilities (File Write, SSRF, Auth Bypass, XSS, JS Execution)
- T1003 OS Credential Dumping
- T1003.001 LSASS Memory
- T1003.002 Security Account Manager
- T1003.003 NTDS
- T1003.004 LSA Secrets
- T1003.005 Cached Domain Credentials
- T1003.006 DCSync
- T1003.007 Proc Filesystem
- T1003.008 /etc/passwd and /etc/shadow
- T1040 Network Sniffing
- T1056 Input Capture
- T1056.001 Keylogging
- T1056.002 GUI Input Capture
- T1056.003 Web Portal Capture
- T1056.004 Credential API Hooking
- T1110 Brute Force
- T1110.001 Password Guessing
- T1110.002 Password Cracking
- T1110.003 Password Spraying
- T1110.004 Credential Stuffing
- T1111 Multi-Factor Authentication Interception
- T1187 Forced Authentication
- T1212 Exploitation for Credential Access
- T1528 Steal Application Access Token
- T1539 Steal Web Session Cookie
- T1552 Unsecured Credentials
- T1552.001 Credentials In Files
- T1552.002 Credentials in Registry
- T1552.003 Bash History
- T1552.004 Private Keys
- T1552.005 Cloud Instance Metadata API
- T1552.006 Group Policy Preferences
- T1552.007 Container API
- T1552.008 Chat Messages
- T1555 Credentials from Password Stores
- T1555.001 Keychain
- T1555.002 Securityd Memory
- T1555.003 Credentials from Web Browsers
- T1555.004 Windows Credential Manager
- T1555.005 Password Managers
- T1555.006 Cloud Secrets Management Stores
- T1556 Modify Authentication Process
- T1556.001 Domain Controller Authentication
- T1556.002 Password Filter DLL
- T1556.003 Pluggable Authentication Modules
- T1556.004 Network Device Authentication
- T1556.005 Reversible Encryption
- T1556.006 Multi-Factor Authentication
- T1556.007 Hybrid Identity
- T1556.008 Network Provider DLL
- T1556.009 Conditional Access Policies
- T1557 Adversary-in-the-Middle
- T1557.001 LLMNR/NBT-NS Poisoning and SMB Relay
- T1557.002 ARP Cache Poisoning
- T1557.003 DHCP Spoofing
- T1557.004 Evil Twin
- T1558 Steal or Forge Kerberos Tickets
- T1558.001 Golden Ticket
- T1558.002 Silver Ticket
- T1558.003 Kerberoasting
- T1558.004 AS-REP Roasting
- T1558.005 Ccache Files
- T1606 Forge Web Credentials
- T1606.001 Web Cookies
- T1606.002 SAML Tokens
- T1621 Multi-Factor Authentication Request Generation
- T1649 Steal or Forge Authentication Certificates
- THREAT-BEC-OAuthDeviceCode Business Email Compromise via OAuth Device Code Flow Phishing
- THREAT-CredentialDump-LSASS LSASS Credential Dumping via Memory Access
- THREAT-EntraID-MFAFatigue Multi-Factor Authentication Fatigue (MFA Bombing) Attack
- THREAT-EntraID-TokenTheft Microsoft Entra ID Session Token Theft and Replay
- THREAT-M365-PasswordSpray Microsoft 365 Password Spray Attack Detection
- THREAT-M365-SuspiciousOAuthConsent Suspicious OAuth Application Consent Grant in Microsoft 365
- THREAT-VPN-CredentialStuffing VPN and Remote Access Credential Stuffing / Brute Force
Related tactics
266 detections
225 detections