Azure Consent To Application
Records consent to an application’s requested permissions.
The adversary is trying to steal account names and passwords.
Credential Access consists of techniques for stealing credentials like account names and passwords. Techniques used to get credentials include keylogging or credential dumping. Using legitimate credentials can give adversaries access to systems, make them harder to detect, and provide the opportunity to create more accounts to help achieve their goals.
In cloud environments, adversaries target API keys, service account credentials, and temporary security tokens. Techniques include querying instance metadata services (IMDS), accessing secrets managers, dumping environment variables from serverless functions, and harvesting credentials from code repositories or CI/CD pipelines.
View Credential Access on MITRE ATT&CK →Explore this tactic in the map.
Records consent to an application’s requested permissions.
Retrieves up to ten named Parameter Store parameters, optionally decrypting SecureString values.
Retrieves encrypted Windows administrator password data for an EC2 instance.
Retrieves the selected version of a Secrets Manager secret.
Retrieves access keys for an Azure App Configuration store.
Retrieves shared keys for an Azure Batch account.
Retrieves the shared admin credentials of an Azure Container Registry.
Requests local cluster-admin kubeconfig credentials for an AKS cluster.
Retrieves the clusterUser kubeconfig for an AKS cluster.
Reads the value of an Azure Key Vault secret.
Retrieves primary and secondary shared keys for a Log Analytics workspace.
Retrieves shared keys and connection strings for a Service Bus namespace authorization rule.
Retrieves an Azure Storage account’s shared access keys.
Regenerates a selected Azure Storage account access key.
Retrieves Azure Functions host, master, and system keys.
Accesses the payload of a Secret Manager secret version.