Credentials from Password Stores: Keychain T1555.001

Tactic: Credential Access

Adversaries may acquire credentials from Keychain. Keychain (or Keychain Services) is the macOS credential management system that stores account names, passwords, private keys, certificates, sensitive application data, payment data, and secure notes. There are three types of Keychains: Login Keychain, System Keychain, and Local Items (iCloud) Keychain. The default Keychain is the Login Keychain, which stores user passwords and information. The System Keychain stores items accessed by the operating system, such as items shared among users on a host. The Local Items (iCloud) Keychain is used for items synced with Apple’s iCloud service.

Events covered

4 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 20 rules share fields, values, and exclusions.

Fields filtered most (22 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType15eq 14, in 1exec, open, modification, rename
process_name12eq 7, in 4, starts_with 1cp, cat, security, bash, curl
CommandLine9contains 6, wildcard 3*/Users/*/Library/Keychains/login.keychain-db*, dump-keychain , export , login-keychain , */Library/Keychains/*
event.type8eq 5, in 3start, process_started
file.name5eq 5login.keychain-db
host.os.type5eq 5
process.args5eq 3, in 1, wildcard 1-d, dump-keychain, -ga, -wa, /Library/Keychains/*
Image3eq 2, wildcard 1/usr/bin/security, /private/var/folders/*.app/*, /volumes/*
parent_process_name2in 2bash, node, osascript, sh, terminal
process.code_signature.exists2eq 2false
process.code_signature.trusted2eq 2false
DestinationHostname1is_null 1
ParentImage1wildcard 1/library/caches/*, /private/tmp/*, /private/var/folders/*
TargetFilename1wildcard 1/users/*/library/keychains/login.keychain-db
event.category1eq 1file

Top indicator values (106 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
EventTypeeq
exec
9579
EventTypeeq
open
552
event.typeeq
start
51087
file.nameeq
login.keychain-db
56
event.typein
process_started
339
event.typein
start
341
process_nameeq
cp
39
process_nameeq
security
24
CommandLinecontains
find-certificate
22
CommandLinecontains
dump-keychain
1
CommandLinecontains
export
13
CommandLinecontains
login-keychain
1
CommandLinecontains
-d
18
CommandLinecontains
-p
1
CommandLinecontains
.keychain
1
CommandLinecontains
/private/var/db/systemkey
1
CommandLinecontains
brave
14
CommandLinecontains
chrome
14
CommandLinecontains
chromium
14
CommandLinecontains
dump-keychain
1
CommandLinecontains
firefox
12
CommandLinecontains
keychain
1
CommandLinewildcard
*/Users/*/Library/Keychains/login.keychain-db*
22
Imageeq
/usr/bin/security
22
process.argseq
-d
212
process.argseq
dump-keychain
22
process.code_signature.existseq
false
2119
process.code_signature.trustedeq
false
2115
process_namein
cat
228
process_namein
cp
218

Exclusions (73 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
CommandLinewildcard
*/Volumes/*/var/db/SystemKey*
1
Effective_process.executablewildcard
/Applications/Claude.app/Contents/MacOS/Claude
1
Effective_process.executablewildcard
/Users/*/Library/Application...
1
Imageeq
/opt/jc/bin/jumpcloud-agent
1
Imageeq
/usr/local/bin/symfony
1
Imagestarts_with
/opt/homebrew/
1
Imagestarts_with
/usr/local/cellar/
1
ParentImageeq
/applications/microsoft...
1
ParentImageeq
/applications/openvpn connect/openvpn connect.app/contents/macos/openvpn connect
1
ParentImageeq
/opt/jc/bin/jumpcloud-agent
1
ParentImagewildcard
/applications/keeper password manager.app/contents/frameworks/keeper...
1
Signatureeq
Software Signing
1
TargetFilenamewildcard
/private/var/*
1
TargetFilenamewildcard
/users/*/library/keychains/*
1
TargetFilenamewildcard
/volumes/*
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform: macOS

Domain: Endpoint

Sigma 2 rules

Elastic 17 rules

Splunk 1 rule