M ManySignal
TA0006 ATT&CK Tactic

Credential Access

Adversaries steal credentials to move freely through your environment as legitimate users. ManySignal detects credential theft at the moment it occurs — before those credentials are weaponised for lateral movement or data exfiltration.

Coverage

Techniques covered
17
Detection rules
61
Avg. detection latency
< 3 min

Threat context

How adversaries steal credentials

Credential theft is the pivot point between initial compromise and full attack execution. Once an adversary has valid credentials — whether a password, a session token, or an API key — they can move laterally, access sensitive data, and establish persistence without triggering the signature-based detections designed for malware. This is why 80%+ of cloud breaches involve credential-based attacks.

Modern credential theft is increasingly targeting the identity layer directly: MFA fatigue bypasses the second factor through social engineering; AiTM proxies capture session tokens post-authentication; Golden SAML forges authentication assertions using stolen cryptographic keys. Defence requires behavioural analytics, not just signature matching.

Credential Access: frequently asked questions

What is ATT&CK Credential Access (TA0006)?

Credential Access covers the techniques adversaries use to steal credentials — passwords, hashes, tokens, session cookies, API keys, and certificates. Stolen credentials enable subsequent lateral movement and persistence while appearing as legitimate user activity.

Which credential access technique is most common in cloud breaches?

MFA fatigue (T1621) and AiTM session token theft (T1539) are the fastest-growing techniques, specifically because they bypass traditional MFA controls. Credential dumping (T1003) remains dominant in Windows environments where attackers gain endpoint access.

How does ManySignal detect credential theft without endpoint access?

Many credential theft techniques leave identity-layer indicators even without endpoint telemetry. MFA fatigue creates an abnormal push volume pattern. Session token theft shows as sessions accessed from new IPs. Credential stuffing generates characteristic failure-then-success patterns on authentication endpoints.

Can ManySignal detect secrets exposed in GitHub repositories?

Yes. Via the GitHub integration, ManySignal ingests Secret Scanning alerts and correlates them with subsequent API calls using those credentials. A detected leaked secret followed by an API call using that secret is a high-confidence indicator of exploitation.

Detect credential theft before it becomes a breach

ManySignal correlates authentication anomalies, endpoint telemetry, and threat intelligence to surface credential theft within minutes.