Forge Web Credentials T1606
Tactic: Credential Access
Adversaries may forge credential materials that can be used to gain access to web applications or Internet services. Web applications and services (hosted in cloud SaaS environments or on-premise servers) often use session cookies, tokens, or other materials to authenticate and authorize user access.
Events covered
5 catalog events are tagged with this technique by at least one rule.
Authoring guide
These 17 rules share fields, values, and exclusions.
Fields filtered most (55 distinct)
These fields appear most often in rule filters.
Top indicator values (100 distinct)
These values appear most often in rule predicates.
Exclusions (2 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 1 rule
Elastic 2 rules
- FortiGate FortiCloud SSO Login from Unusual Source
- M365 Identity Unusual SSO Authentication Errors for User
Kusto 14 rules
- [Entra ID] Suspicious Continuous OAuth Token Usage
- Azure secure score PW age policy new
- Cross-Cloud Unauthorized Credential Access Detection From AWS RDS Login
- Detect device token stealing with WDAC
- Detect entra token request via specific BOF (IOC based)
- Detect Multiple Hello for Business PRT tokens being used simultaneously for one device.
- Detect suspicious foci token logins
- Detect suspicious foci token logins V2
- Detect Suspicious ncrypt.dll usage by CLI tool or unknown process
- Detect Suspicious ncrypt.dll usage by process requesting Entra ID Nonce
- Detect Suspicious ncrypt.dll usage on admin device with RDP connections to non TPM protected device
- Detect Suspicious ncrypt.dll usage with RDP connections to unmanaged or non TPM protected device
- SAP BTP - Cloud Identity Service application configuration monitor
- SAP BTP - Trust and authorization Identity Provider monitor