D3-CCSA
Credential Compromise Scope Analysis
Description
Determining which credentials may have been compromised by analyzing the user logon history of a particular system.
Mapped SPARTA techniques
No techniques mapped to this control.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Counters 19 in MITRE ATT&CK Enterprise
- T1003.003NTDS
- T1003.005Cached Domain Credentials
- T1003.008/etc/passwd and /etc/shadow
- T1098.001Additional Cloud Credentials
- T1110.001Password Guessing
- T1110.002Password Cracking
- T1110.003Password Spraying
- T1134.001Token Impersonation/Theft
- T1134.002Create Process with Token
- T1134.003Make and Impersonate Token
- T1528Steal Application Access Token
- T1539Steal Web Session Cookie
- T1550.001Application Access Token
- T1550.004Web Session Cookie
- T1552Unsecured Credentials
- T1558Steal or Forge Kerberos Tickets
- T1558.001Golden Ticket
- T1606Forge Web Credentials
- T1606.001Web Cookies
Cite as SafeMode Space, d3fend D3-CCSA.