T1550.001 Application Access Token
Subtécnica de T1550 Use Alternate Authentication Material
Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote systems. These tokens are typically stolen from users or services and used in lieu of login credentials. Application access tokens are used to make authorized API requests on behalf of a user or service and are commonly used to…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- AWS Console GetSigninToken Potential Abusemediumtest · aws
- AWS Suspicious SAML Activitymediumtest · aws
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.