AWS GetAuthorizationToken
Retrieves an ECR authorization token for Docker image operations, seen in container escape and lateral movement chains.
Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. [Shell History](https://attack.mitre.org/techniques/T1552/003)), operating system or applica...
View on MITRE ATT&CK →Retrieves an ECR authorization token for Docker image operations, seen in container escape and lateral movement chains.
Retrieves the encrypted Windows administrator password for a newly launched EC2 Windows instance.
Lists the access keys for an Azure App Configuration store, exposing credentials used to read or write configuration data.
Reads credential assets stored in an Azure Automation account, potentially exposing sensitive authentication data.
Lists the access keys for an Azure Batch account, exposing credentials used to authenticate Batch API calls.
Lists the admin credentials for an Azure Container Registry, exposing the username and password for registry access.
Retrieves the cluster-admin kubeconfig for an AKS cluster, granting full administrative access to the cluster.
Retrieves the user-level kubeconfig for an AKS cluster.
Retrieves the primary and secondary access keys for a Log Analytics workspace.
Lists the access keys for an Azure Service Bus namespace authorization rule, exposing connection strings for messaging.
Lists the access keys for an Azure Storage account, exposing credentials that provide full data-plane access.
Regenerates one of the two access keys for an Azure Storage account, invalidating the previous key.
Lists the host keys for an Azure App Service or Azure Functions app, exposing function-level and master access keys.