SIGNAL//DESK
AI securitysrc: MITRE ATLAS

Exploitation for Credential Access

Exploitation for Credential Access is when a hacker uses a mistake in a computer program's code to break into a system and steal usernames and passwords, much like using a hidden spare key that was left out by mistake to enter a locked room.

This refers to the technique where an adversary leverages a software vulnerability—such as a buffer overflow or injection flaw—to gain unauthorized execution privileges, subsequently using that access to harvest sensitive authentication data like credentials from memory, configuration files, or databases.

Adversaries may exploit software vulnerabilities in an attempt to collect credentials. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code, thereby facilitating the unauthorized extraction of authentication artifacts, tokens, or plaintext credentials from the compromised environment.


← all terms