Forge Web Credentials T1606

Tactic: Credential Access

Adversaries may forge credential materials that can be used to gain access to web applications or Internet services. Web applications and services (hosted in cloud SaaS environments or on-premise servers) often use session cookies, tokens, or other materials to authenticate and authorize user access.

Events covered

5 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 17 rules share fields, values, and exclusions.

Fields filtered most (55 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
ActionType5starts_with 5, eq 2AppControl, ConnectionSuccess
file_name5eq 5ncrypt.dll, microsoftaccounttokenprovider.dll
parent_process_name4contains 2, ne 2microsoft.tri.sensor.exe, powershell, python
DestinationHostname3eq 3login.microsoftonline.com
GlobalPrevalence3lt 3250
IncomingTokenType3eq 3, ne 2none, primaryRefreshToken
type3eq 3DeviceInventoryId, IdentityProvider
AppDisplayName2cross_field_compare 1, eq 1Azure Portal, SecondAppDisplayName
AppId2eq 2FociClientApplications
DestinationPort2eq 23389
HomeTenantId2cross_field_compare 2ResourceTenantId
NodeLabel2eq 2device
OnboardingStatus2ne 2Onboarded
SecondAppDisplayName2in 2Microsoft Azure CLI, Microsoft Azure PowerShell, Copilot App, Office 365 Management
TimeDiff2ge 2, le 10, 1, 90

Top indicator values (100 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
ActionTypestarts_with
AppControl
55
ActionTypestarts_with
ConnectionSuccess
1
file_nameeq
ncrypt.dll
44
DestinationHostnameeq
login.microsoftonline.com
33
GlobalPrevalencelt
250
34
ActionTypeeq
ConnectionSuccess
211
AppIdeq
FociClientApplications
22
DestinationPorteq
3389
212
HomeTenantIdcross_field_compare
ResourceTenantId
23
IncomingTokenTypeeq
none
22
IncomingTokenTypene
none
22
NodeLabeleq
device
23
OnboardingStatusne
Onboarded
25
SecondAppDisplayNamein
Microsoft Azure CLI
22
SecondAppDisplayNamein
Microsoft Azure PowerShell
22
TpmActivatedne
true
24
TpmEnabledne
true
24
TpmSupportedne
true
24
event.categoryeq
authentication
234
parent_process_namecontains
powershell
22
parent_process_namecontains
python
22
parent_process_namene
microsoft.tri.sensor.exe
23
typeeq
DeviceInventoryId
25
ActivityTypecontains
credentialaccess:rds/anomalousbehavior.successfulbruteforce
12
ActivityTypecontains
credentialaccess:rds/anomalousbehavior.successfullogin
1
ActivityTypecontains
credentialaccess:rds/maliciousipcaller.failedlogin
1
ActivityTypecontains
credentialaccess:rds/maliciousipcaller.successfullogin
1
ActivityTypecontains
credentialaccess:rds/toripcaller.failedlogin
12
ActivityTypecontains
credentialaccess:rds/toripcaller.successfullogin
12
AppDisplayNamecross_field_compare
SecondAppDisplayName
1

Exclusions (2 distinct)

These values appear most often in top-level exclusions.

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 1 rule

Elastic 2 rules

Kusto 14 rules