Picus Security Analyzes MITRE ATT&CK T1555 Vulnerability
Picus Security has published an analysis of the MITRE ATT&CK T1555 technique, "Credentials from Password Stores." Attackers exploit this method to gain unauthorized access to systems through stored credentials.

Cybersecurity firm Picus Security has released a detailed analysis of the MITRE ATT&CK framework technique T1555, known as "Credentials from Password Stores." This technique allows adversaries to harvest credentials stored by users in password managers and browser credential stores, often providing a direct route to sensitive systems.
The technique capitalizes on user convenience, where complex passwords are saved for easier access. However, this practice creates attractive targets for cybercriminals. If an attacker gains access to these repositories, they can obtain credentials that unlock access to enterprise networks, cloud services, and critical applications.
Picus Security explains that attackers often aim to compromise the device or application hosting the password store. This initial access can be achieved through methods like phishing (T1566) or exploiting public-facing applications (T1190). Once inside, attackers may attempt to decrypt or directly extract stored credentials, enabling privilege escalation and lateral movement within the network.
By utilizing these harvested credentials, attackers can bypass other security controls, such as multi-factor authentication (MFA), or impersonate legitimate users. Privileged account or service account credentials, in particular, are highly valuable for expanding an attack's scope or achieving complete network compromise. Picus Security provides tools for organizations to test and enhance their defenses against such techniques.