Cybersecurity from Málaga · Networks, lures and threats

← Threats
MITRE ATT&CK technique · Lateral Movement

T1550.001 Application Access Token

Sub-technique of T1550 Use Alternate Authentication Material

Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote systems. These tokens are typically stolen from users or services and used in lieu of login credentials. Application access tokens are used to make authorized API requests on behalf of a user or service and are commonly used to…

MITRE ATT&CK page ↗

Who uses it · with stories on Jábega

Sigma rules to hunt it

Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.