Credentials from Password Stores: Keychain T1555.001
Tactic: Credential Access
Adversaries may acquire credentials from Keychain. Keychain (or Keychain Services) is the macOS credential management system that stores account names, passwords, private keys, certificates, sensitive application data, payment data, and secure notes. There are three types of Keychains: Login Keychain, System Keychain, and Local Items (iCloud) Keychain. The default Keychain is the Login Keychain, which stores user passwords and information. The System Keychain stores items accessed by the operating system, such as items shared among users on a host. The Local Items (iCloud) Keychain is used for items synced with Apple’s iCloud service.
Events covered
4 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| ESF | exec | Process Execution |
| ESF | open | File Open |
| ESF | rename | File Rename |
| ESF | write | File Write |
Authoring guide
These 20 rules share fields, values, and exclusions.
Fields filtered most (22 distinct)
These fields appear most often in rule filters.
Top indicator values (106 distinct)
These values appear most often in rule predicates.
Exclusions (73 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Platform: macOS
Domain: Endpoint
Sigma 2 rules
Elastic 17 rules
- Dumping of Keychain Content via Security Command
- First Time Python Accessed Sensitive Credential Files
- Keychain CommandLine Interaction via Unsigned or Untrusted Process
- Keychain Credential Files Collected via Archive Utility
- Keychain Dump via Native Security Tool
- Keychain Password Retrieval via Command Line
- Suspicious User Keychain Access via Nodejs
- Suspicious User Keychain DB Access by Unsigned Binary
- SystemKey Access via Command Line
- SystemKey Access via Command Line
- User Keychain Access in Unusual Location
- User Keychain copied via Script Interpreter
- User Keychain copied via Shell interpreter
- User Keychain Copied via Suspicious Parent
- User Keychain DB Access by Osascript
- User Keychain DB Access by Self-Signed Binary
- User Keychain Exfiltration via Curl