166 terms · 75/46/45
Technique № 003 · class: initial access

Credential Abuse

Credential abuse involves using stolen, leaked, or otherwise obtained login data to gain unauthorized access to systems and services. The attacker impersonates a legitimate user.

Term

description · examples · notes

Credential abuse involves using stolen, leaked, or otherwise obtained login data to gain unauthorized access to systems and services. The attacker impersonates a legitimate user.

Description

This technique is particularly dangerous because it requires no vulnerability exploitation, and the attacker's activities are hard to distinguish from normal authorized user behavior.

Examples

  • Logging into a corporate VPN with credentials stolen via an infostealer
  • Using leaked passwords to access an email account
  • Logging into an admin panel with credentials purchased on an underground market

Notes

  • Multi-factor authentication significantly hinders abuse even of compromised credentials.

Mentioned in the news

Composite

Threats

used by 40

Defenses

countered by 15